CVE-2025-24893

critical

Description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity and availability of the whole XWiki installation. To reproduce on an instance, without being logged in, go to `<host>/xwiki/bin/get/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7Dprintln%28"Hello%20from"%20%2B%20"%20search%20text%3A"%20%2B%20%2823%20%2B%2019%29%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D%20`. If there is an output, and the title of the RSS feed contains `Hello from search text:42`, then the instance is vulnerable. This vulnerability has been patched in XWiki 15.10.11, 16.4.1 and 16.5.0RC1. Users are advised to upgrade. Users unable to upgrade may edit `Main.SolrSearchMacros` in `SolrSearchMacros.xml` on line 955 to match the `rawResponse` macro in `macros.vm#L2824` with a content type of `application/xml`, instead of simply outputting the content of the feed.

References

https://github.com/vasilysaint/CVE-2025-24893

https://github.com/hasecto/CVE-2025-24893

https://github.com/ZeroTrustWraith/Exploit-PoC

https://github.com/Carsonregular365/Exploit-Hub

https://github.com/Retro023/MY-CVE-POC-s

https://github.com/nohack1212/CVE-2025-24893-

https://github.com/WhiteDominion/CVE-2025-24893

https://github.com/32BitZ-Studio/Total-POC-CVE

https://github.com/B1ack4sh/Blackash-CVE-2025-24893

https://github.com/pwnk1t/cve-collection

https://github.com/rvizx/CVE-2025-24893

https://github.com/bj715/TDCVES

https://github.com/Yukik4z3/CVE-2025-24893

https://github.com/AliAmouz/CVE2025-24893

https://github.com/andwati/CVE-2025-24893

https://github.com/ashdxt/CVE-POC

https://github.com/ibadovulfat/CVE-2025-24893_HackTheBox-Editor-Writeup

https://github.com/x0da6h/POC-for-CVE-2025-24893

https://github.com/x0da6h/EXP-for-CVE-2025-24893

https://github.com/KobyGarbrah/Exploits

https://github.com/D3Ext/CVE-2025-24893

https://github.com/Hex00-0x4/CVE-2025-24893-XWiki-RCE

https://github.com/Th3Gl0w/CVE-2025-24893-POC

https://github.com/hackersonsteroids/cve-2025-24893

https://github.com/AliElKhatteb/CVE-2024-32019-POC

https://github.com/Net-Doge/CVE-POCs

https://github.com/nopgadget/CVE-2025-24893

https://github.com/0xVoodoo/PoCs

https://github.com/ibrahimsql/cve-2025-24893

https://github.com/Kai-One001/cve-

https://github.com/iSee857/CVE-2025-24893-PoC

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24893

https://jira.xwiki.org/browse/XWIKI-22149

https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-rr6p-3pfg-562j

https://github.com/xwiki/xwiki-platform/commit/67021db9b8ed26c2236a653269302a86bf01ef40

https://github.com/xwiki/xwiki-platform/blob/67021db9b8ed26c2236a653269302a86bf01ef40/xwiki-platform-core/xwiki-platform-web/xwiki-platform-web-templates/src/main/resources/templates/macros.vm#L2824

https://github.com/xwiki/xwiki-platform/blob/568447cad5172d97d6bbcfda9f6183689c2cf086/xwiki-platform-core/xwiki-platform-search/xwiki-platform-search-solr/xwiki-platform-search-solr-ui/src/main/resources/Main/SolrSearchMacros.xml#L955

Details

Source: Mitre, NVD

Published: 2025-02-20

Updated: 2025-10-31

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.99864

Vulnerability Watch

Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.

Vulnerability Being Monitored