Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p9qm-p942-q3w5

Опубликовано: 25 июл. 2025
Источник: github
Github: Прошло ревью
CVSS4: 8.6

Описание

XWiki Platform vulnerable to SQL injection through XWiki#searchDocuments API

Impact

It's possible to execute any SQL query in Oracle by using the function like DBMS_XMLGEN or DBMS_XMLQUERY.

The XWiki#searchDocuments APIs are not sanitizing the query at all and even if they force a specific select, Hibernate allows using any native function in an HQL query (for example in the WHERE).

Patches

This has been patched in 16.10.6 and 17.3.0-rc-1.

Workarounds

There is no known workaround, other than upgrading XWiki.

References

https://jira.xwiki.org/browse/XWIKI-22728

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

org.xwiki.platform:xwiki-platform-oldcore

maven
Затронутые версииВерсия исправления

>= 1.0, < 16.10.6

16.10.6

Наименование

org.xwiki.platform:xwiki-platform-oldcore

maven
Затронутые версииВерсия исправления

>= 17.0.0-rc1, < 17.3.0-rc-1

17.3.0-rc-1

EPSS

Процентиль: 72%
0.00719
Низкий

8.6 High

CVSS4

Дефекты

CWE-20
CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
7 месяцев назад

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions between 17.0.0-rc1 to 17.2.2 and versions 16.10.5 and below, it's possible to execute any SQL query in Oracle by using the function like DBMS_XMLGEN or DBMS_XMLQUERY. The XWiki#searchDocuments APIs pass queries directly to Hibernate without sanitization. Even when these APIs enforce a specific SELECT clause, attackers can still inject malicious code through HQL's native function support in other parts of the query (such as the WHERE clause). This is fixed in versions 16.10.6 and 17.3.0-rc-1.

CVSS3: 4.7
fstec
7 месяцев назад

Уязвимость платформы создания совместных веб-приложений XWiki Platform XWiki, связанная с недостаточной проверкой входных данных, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 72%
0.00719
Низкий

8.6 High

CVSS4

Дефекты

CWE-20
CWE-89