First published: Fri Mar 07 2025(Updated: )
### Impact A user that doesn't have programming rights can execute arbitrary code when creating a page using the Migration Page template. A possible attack vector is the following: * Create a page and add the following content: ``` confluencepro.job.question.advanced.input={{/html}} {{async async="true" cached="false" context="doc.reference"}}{{groovy}}println("hello from groovy!"){{/groovy}}{{/async}} ``` * Use the object editor to add an object of type `XWiki.TranslationDocumentClass` with scope `USER`. * Access an unexisting page using the `MigrationTemplate` ``` http://localhost:8080/xwiki/bin/edit/Page123?template=ConfluenceMigratorPro.Code.MigrationTemplate ``` It is expected that `{{/html}} {{async async="true" cached="false" context="doc.reference"}}{{groovy}}println("hello from groovy!"){{/groovy}}{{/async}}` will be present on the page, however, `hello from groovy` will be printed. ### Patches The issue will be fixed as part of v1.2. The fix was added with commit [35cef22](https://github.com/xwikisas/application-confluence-migrator-pro/commit/36cef2271bd429773698ca3a21e47b6d51d6377d) ### Workarounds There are no known workarounds besides upgrading. ### References No references.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/com.xwiki.confluencepro:application-confluence-migrator-pro-ui | >=1.0<1.2.0 | 1.2.0 |
XWiki Confluence Migrator Pro | <1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27603 is classified as a high severity vulnerability due to the potential for arbitrary code execution.
To fix CVE-2025-27603, upgrade XWiki Confluence Migrator Pro to version 1.2.0 or later.
CVE-2025-27603 affects users of XWiki Confluence Migrator Pro versions prior to 1.2.0.
CVE-2025-27603 is an arbitrary code execution vulnerability stemming from an unescaped translation issue.
Yes, users without programming rights can exploit CVE-2025-27603 to execute arbitrary code when creating a page.