漏洞描述 XWiki Platform 4.2-milestone-2 至 16.10.6 存在路径遍历漏洞。该漏洞由于 jsx 和 sx 端点的访问控制不当,允许远程攻击者读取敏感的配置文件。此漏洞的利用不需要特殊权限,可能导致敏感系统信息的泄露。
相关漏洞推荐 POC CVE-2025-32429: XWiki Platform - SQL Injection XWiki Platform /bin/register/XWiki/XWikiRegister 代码执行漏洞(CVE-2024-21650) XWiki Platform /rest/wikis/xwiki/pages 权限绕过漏洞(CVE-2025-29925) POC CVE-2023-37462: XWiki Platform - Remote Code Execution POC CVE-2024-45591: XWiki Platform - Unauthorized Document History Access POC CVE-2025-24893: XWiki Platform - Remote Code Execution POC CVE-2025-32430: XWiki Platform - Cross-Site Scripting POC CVE-2025-55747: XWiki Platform - Information Disclosure POC CVE-2025-55748: XWiki Platform - Path Traversal XWiki Platform /bin/view/ 代码执行漏洞(CVE-2023-37462)