漏洞描述 XWiki Platform 4.2-milestone-2 至 16.10.6 存在路径遍历漏洞。该漏洞由于 jsx 和 sx 端点的访问控制不当,允许远程攻击者读取敏感的配置文件。此漏洞的利用不需要特殊权限,可能导致敏感系统信息的泄露。
相关漏洞推荐 POC CVE-2019-4061: IBM BigFix Platform - Information Disclosure POC CVE-2025-55749: XWiki - Information Disclosure POC 红海云eHR /RedseaPlatform/BossIndex.mob SQL 注入漏洞 XWiki Jetty /webapps/xwiki/WEB-INF/web.xml 文件读取漏洞(CVE-2025-55749) XWiki Platform 文件读取漏洞(CVE-2025-55749) XWiki /rest/wikis/xwiki/query SQL 注入漏洞(CVE-2025-32969) POC CVE-2025-51991: XWiki <= 17.3.0 - Server-Side Template Injection (SSTI) POC CVE-2025-51990: XWiki – Stored Cross-Site Scripting (XSS) POC CVE-2025-32429: XWiki Platform - SQL Injection POC CVE-2025-52472: XWiki - HQL Injection XWiki Platform /bin/register/XWiki/XWikiRegister 代码执行漏洞(CVE-2024-21650) (CVE-2025-55747) XWiki Platform配置文件信息泄露漏洞 (CVE-2025-52472) XWiki REST搜索URL HQL注入漏洞(orderField参数)