漏洞描述 XWiki Platform是XWiki基金会的一套用于创建Web协作应用程序的Wiki平台。XWiki Platform存在安全漏洞,该漏洞源于user registration功存在一个代码注入漏洞,未经授权的攻击者可以利用该漏洞在服务器上执行任意代码。
相关漏洞推荐 POC CVE-2025-32429: XWiki Platform - SQL Injection XWiki Platform /bin/ssx/Main/WebHome 目录遍历漏洞(CVE-2025-55748) XWiki Platform /rest/wikis/xwiki/pages 权限绕过漏洞(CVE-2025-29925) POC CVE-2023-37462: XWiki Platform - Remote Code Execution POC CVE-2024-45591: XWiki Platform - Unauthorized Document History Access POC CVE-2025-24893: XWiki Platform - Remote Code Execution POC CVE-2025-32430: XWiki Platform - Cross-Site Scripting POC CVE-2025-55747: XWiki Platform - Information Disclosure POC CVE-2025-55748: XWiki Platform - Path Traversal XWiki Platform /bin/view/ 代码执行漏洞(CVE-2023-37462)