CVE-2025-29925

Description

XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, protected pages are listed when requesting the REST endpoints /rest/wikis/[wikiName]/pages even if the user doesnt have view rights on them. Its particularly true if the entire wiki is protected with "Prevent unregistered user to view pages": the endpoint would still list the pages of the wiki, though only for the main wiki. The problem has been patched in XWiki 15.10.14, 16.4.6, 16.10.0RC1. In those versions the endpoint can still be requested but the result is filtered out based on pages rights.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.391

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2025-29925 are fixed in XWiki-platform-rest-server 15.10.14Windows
Vulnerabilities CVE-2025-29925,CVE-2025-32969 are fixed in XWiki-platform-rest-server 16.4.6Windows
Vulnerabilities CVE-2025-29925 are fixed in XWiki-platform-rest-server 16.10.0Windows
Vulnerabilities CVE-2025-29925 are fixed in XWiki-platform-rest-server for Linux 15.10.14Linux
Vulnerabilities CVE-2025-29925,CVE-2025-32969 are fixed in XWiki-platform-rest-server for Linux 16.4.6Linux
Vulnerabilities CVE-2025-29925 are fixed in XWiki-platform-rest-server for Linux 16.10.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234