Логотип exploitDog
bind:CVE-2025-32971
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-32971

Количество 3

Количество 3

nvd логотип

CVE-2025-32971

9 месяцев назад

XWiki is a generic wiki platform. In versions starting from 4.5.1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0-rc-1, the Solr script service doesn't take dropped programming rights into account. The Solr script service that is accessible in XWiki's scripting API normally requires programming rights to be called. Due to using the wrong API for checking rights, it doesn't take the fact into account that programming rights might have been dropped by calling `$xcontext.dropPermissions()`. If some code relies on this for the safety of executing Velocity code with the wrong author context, this could allow a user with script rights to either cause a high load by indexing documents or to temporarily remove documents from the search index. This issue has been patched in versions 15.10.13, 16.4.4, and 16.8.0-rc-1.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-987p-r3jc-8c8v

10 месяцев назад

Solr script service doesn't take dropped programming right into account

CVSS3: 3.8
EPSS: Низкий
fstec логотип

BDU:2025-13435

10 месяцев назад

Уязвимость сервиса скриптов Solr платформы создания совместных веб-приложений XWiki Platform XWiki , позволяющая нарушителю удалять произвольные файлы

CVSS3: 3.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-32971

XWiki is a generic wiki platform. In versions starting from 4.5.1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0-rc-1, the Solr script service doesn't take dropped programming rights into account. The Solr script service that is accessible in XWiki's scripting API normally requires programming rights to be called. Due to using the wrong API for checking rights, it doesn't take the fact into account that programming rights might have been dropped by calling `$xcontext.dropPermissions()`. If some code relies on this for the safety of executing Velocity code with the wrong author context, this could allow a user with script rights to either cause a high load by indexing documents or to temporarily remove documents from the search index. This issue has been patched in versions 15.10.13, 16.4.4, and 16.8.0-rc-1.

CVSS3: 3.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-987p-r3jc-8c8v

Solr script service doesn't take dropped programming right into account

CVSS3: 3.8
0%
Низкий
10 месяцев назад
fstec логотип
BDU:2025-13435

Уязвимость сервиса скриптов Solr платформы создания совместных веб-приложений XWiki Platform XWiki , позволяющая нарушителю удалять произвольные файлы

CVSS3: 3.8
0%
Низкий
10 месяцев назад

Уязвимостей на страницу