CVE Vulnerabilities

CVE-2025-49580

Incorrect Privilege Assignment

Published: Jun 13, 2025 | Modified: Sep 03, 2025
CVSS 3.x
8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

XWiki is a generic wiki platform. From 8.2 and 7.4.5 until 17.1.0-rc-1, 16.10.4, and 16.4.7, pages can gain script or programming rights when they contain a link and the target of the link is renamed or moved. This might lead to execution of scripts contained in xobjects that should have never been executed. This vulnerability is fixed in 17.1.0-rc-1, 16.10.4, and 16.4.7.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Xwiki Xwiki 7.4.5 (including) 16.4.7 (excluding)
Xwiki Xwiki 16.5.0 (including) 16.10.4 (excluding)
Xwiki Xwiki 17.0.0 (including) 17.1.0 (excluding)

Potential Mitigations

References