CNNVD-202506-1788 Information
CNNVD ID
CNNVD-202506-1788
Related CVE
- CNNVD Published: 2025-06-13
Description (Chinese)
XWiki Platform是XWiki开源的一套用于创建Web协作应用程序的Wiki平台。 XWiki Platform 15.10.16之前版本、16.0.0-rc-1至16.4.6版本和16.5.0-rc-1至16.10.1版本存在安全漏洞,该漏洞源于XClass定义可能导致执行恶意代码。
Description (English)
XWiki Platform is an open source of XWiki ’ s Wiki platform for creating a Web collaborative application. Prior to the XWiki Platform 15.10.16, 16.0.0-rc-1 to 16.4.6 and 16.5.0-rc-1 to 16.10.1, there was a security loophole, which stemmed from the XClass definition that could lead to the implementation of malicious codes.
Hazard Level
Medium
Vulnerability Type
其他
Affected Vendor
XWiki
Published
2025-06-13
Last Modified
2026-02-24
References
https://github.com/xwiki/xwiki-platform/commit/385bde985cdb61ebf315d30c0b144b6d2e2c2d45 https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-59w6-r9hm-439h https://jira.xwiki.org/browse/XWIKI-22476 https://access.redhat.com/security/cve/cve-2025-49585
Patch
https://www.xwiki.org/xwiki/bin/view/Download/
Share on: