Логотип exploitDog
bind:CVE-2025-29925
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-29925

Количество 3

Количество 3

nvd логотип

CVE-2025-29925

8 месяцев назад

XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, protected pages are listed when requesting the REST endpoints /rest/wikis/[wikiName]/pages even if the user doesn't have view rights on them. It's particularly true if the entire wiki is protected with "Prevent unregistered user to view pages": the endpoint would still list the pages of the wiki, though only for the main wiki. The problem has been patched in XWiki 15.10.14, 16.4.6, 16.10.0RC1. In those versions the endpoint can still be requested but the result is filtered out based on pages rights.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-22q5-9phm-744v

8 месяцев назад

XWiki allows unregistered users to access private pages information through REST endpoint

EPSS: Низкий
fstec логотип

BDU:2025-03253

8 месяцев назад

Уязвимость компонента org.xwiki.platform:xwiki-platform-rest-server платформы создания совместных веб-приложений XWiki Platform, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-29925

XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, protected pages are listed when requesting the REST endpoints /rest/wikis/[wikiName]/pages even if the user doesn't have view rights on them. It's particularly true if the entire wiki is protected with "Prevent unregistered user to view pages": the endpoint would still list the pages of the wiki, though only for the main wiki. The problem has been patched in XWiki 15.10.14, 16.4.6, 16.10.0RC1. In those versions the endpoint can still be requested but the result is filtered out based on pages rights.

CVSS3: 5.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-22q5-9phm-744v

XWiki allows unregistered users to access private pages information through REST endpoint

0%
Низкий
8 месяцев назад
fstec логотип
BDU:2025-03253

Уязвимость компонента org.xwiki.platform:xwiki-platform-rest-server платформы создания совместных веб-приложений XWiki Platform, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.5
0%
Низкий
8 месяцев назад

Уязвимостей на страницу