CVE-2025-29925
Description
XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, protected pages are listed when requesting the REST endpoints /rest/wikis/[wikiName]/pages even if the user doesnt have view rights on them. Its particularly true if the entire wiki is protected with "Prevent unregistered user to view pages": the endpoint would still list the pages of the wiki, though only for the main wiki. The problem has been patched in XWiki 15.10.14, 16.4.6, 16.10.0RC1. In those versions the endpoint can still be requested but the result is filtered out based on pages rights.
Risk Information
Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.391
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2025-29925 are fixed in XWiki-platform-rest-server 15.10.14 | Windows |
| Vulnerabilities CVE-2025-29925,CVE-2025-32969 are fixed in XWiki-platform-rest-server 16.4.6 | Windows |
| Vulnerabilities CVE-2025-29925 are fixed in XWiki-platform-rest-server 16.10.0 | Windows |
| Vulnerabilities CVE-2025-29925 are fixed in XWiki-platform-rest-server for Linux 15.10.14 | Linux |
| Vulnerabilities CVE-2025-29925,CVE-2025-32969 are fixed in XWiki-platform-rest-server for Linux 16.4.6 | Linux |
| Vulnerabilities CVE-2025-29925 are fixed in XWiki-platform-rest-server for Linux 16.10.0 | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234