CVE-2025-24893: XWiki Platform Eval Injection Vulnerability

Published Feb 20, 2025
·
Updated

Impact Any guest can perform arbitrary remote code execution through a request to SolrSearch. This impacts the confidentiality, integrity and availability of the whole XWiki installation.

To reproduce on an instance, without being logged in, go to <host>/xwiki/bin/get/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7Dprintln%28"Hello%20from"%20%2B%20"%20search%20text%3A"%20%2B%20%2823%20%2B%2019%29%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D%20. If there is an output, and the title of the RSS feed contains Hello from search text:42, then the instance is vulnerable.

Patches This vulnerability has been patched in XWiki 15.10.11, 16.4.1 and 16.5.0RC1.

Workarounds This line in Main.SolrSearchMacros can be edited to match the rawResponse macro defined here with a content type of application/xml, instead of simply outputting the content of the feed.

References

https://jira.xwiki.org/browse/XWIKI-22149 https://github.com/xwiki/xwiki-platform/commit/67021db9b8ed26c2236a653269302a86bf01ef40

Attribution This vulnerability has been reported by John Kwak for Trend Micro's Zero Day Initiative.

Other sources

XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch.

CISA

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to SolrSearch. This impacts the confidentiality, integrity and availability of the whole XWiki installation. To reproduce on an instance, without being logged in, go to <host>/xwiki/bin/get/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7Dprintln%28"Hello%20from"%20%2B%20"%20search%20text%3A"%20%2B%20%2823%20%2B%2019%29%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D%20. If there is an output, and the title of the RSS feed contains Hello from search text:42, then the instance is vulnerable. This vulnerability has been patched in XWiki 15.10.11, 16.4.1 and 16.5.0RC1. Users are advised to upgrade. Users unable to upgrade may edit Main.SolrSearchMacros in SolrSearchMacros.xml on line 955 to match the rawResponse macro in macros.vm#L2824 with a content type of application/xml, instead of simply outputting the content of the feed.

NVD

Affected Software

9 affected componentsFixes available
XWiki XWiki Platform<15.10.11, <16.4.1, <16.5.0RC1
maven/org.xwiki.platform:xwiki-platform-search-solr-ui>=16.0.0-rc-1<16.4.1
16.4.1
maven/org.xwiki.platform:xwiki-platform-search-solr-ui>=5.3-milestone-2<15.10.11
15.10.11
XWiki xwiki>=5.4<15.10.11
XWiki xwiki>=16.0.0<16.4.1
XWiki xwiki=5.3
XWiki xwiki=5.3-milestone2
XWiki xwiki=5.3-rc1
XWiki Platform

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade maven/org.xwiki.platform:xwiki-platform-search-solr-ui to a version that resolves this vulnerability.

    Fixed in 16.4.1
  2. Upgrade

    Upgrade maven/org.xwiki.platform:xwiki-platform-search-solr-ui to a version that resolves this vulnerability.

    Fixed in 15.10.11
  3. Upgrade

    Upgrade maven/org.xwiki.platform:xwiki-platform-search-solr-ui to a version that resolves this vulnerability.

    Fixed in 16.5.0RC1
  4. Configuration

    Edit Main.SolrSearchMacros (around line 955 in SolrSearchMacros.xml) to match the rawResponse macro definition and output with content type application/xml instead of directly outputting the feed content.

    Main.SolrSearchMacros (SolrSearchMacros.xml) SolrSearch macro output handling = use rawResponse macro with content type application/xml
  5. Compensating control

    Apply vendor-provided mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Event History

Feb 20, 2025
CVE Published
via MITRE·07:19 PM
Data Sourced
via MITRE·07:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·08:16 PM
Apr 7, 2025
Exploit Published
12:00 AM
Sep 16, 2025
Exploit Published
12:00 AM
Oct 30, 2025
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
Nov 17, 2025
News Published
via BleepingComputer·10:41 PM
News Published
via BleepingComputer·10:43 PM
Dec 31, 2025
News Published
via BleepingComputer·02:58 PM
Mar 9, 2026
News Published
via BleepingComputer·09:45 PM
Mar 13, 2026
News Published
via ZDNet·05:40 PM
News Published
via ZDNet·06:33 PM
May 18, 2026
News Published
via ZDNet·08:13 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-24893?

CVE-2025-24893 is a high-severity vulnerability that allows arbitrary remote code execution.

2

How do I fix CVE-2025-24893?

To fix CVE-2025-24893, you should upgrade your XWiki Platform to a version higher than 16.5.0RC1.

3

What products are affected by CVE-2025-24893?

CVE-2025-24893 affects XWiki Platform versions up to 15.10.11, 16.4.1, and 16.5.0RC1.

4

Who can exploit CVE-2025-24893?

Any guest user can exploit CVE-2025-24893 to perform remote code execution through a request to SolrSearch.

5

What impact does CVE-2025-24893 have?

CVE-2025-24893 impacts the confidentiality, integrity, and availability of the entire XWiki installation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203