CVE-2025-32969

Description

XWiki is a generic wiki platform. In versions starting from 1.8 and prior to 15.10.16, 16.4.6, and 16.10.1, it is possible for a remote unauthenticated user to escape from the HQL execution context and perform a blind SQL injection to execute arbitrary SQL statements on the database backend, including when "Prevent unregistered users from viewing pages, regardless of the page rights" and "Prevent unregistered users from editing pages, regardless of the page rights" options are enabled. Depending on the used database backend, the attacker may be able to not only obtain confidential information such as password hashes from the database, but also execute UPDATE/INSERT/DELETE queries. This issue has been patched in versions 16.10.1, 16.4.6 and 15.10.16. There is no known workaround, other than upgrading XWiki.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
26.184

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2025-29925,CVE-2025-32969 are fixed in XWiki-platform-rest-server 16.4.6Windows
Vulnerabilities CVE-2025-32969 are fixed in XWiki-platform-rest-server 15.10.16Windows
Vulnerabilities CVE-2025-32969 are fixed in XWiki-platform-rest-server 16.10.1Windows
Vulnerabilities CVE-2025-29925,CVE-2025-32969 are fixed in XWiki-platform-rest-server for Linux 16.4.6Linux
Vulnerabilities CVE-2025-32969 are fixed in XWiki-platform-rest-server for Linux 15.10.16Linux
Vulnerabilities CVE-2025-32969 are fixed in XWiki-platform-rest-server for Linux 16.10.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234