CNNVD-202506-1793 Information

CNNVD ID

CNNVD-202506-1793

CVE-2025-49587

  • CNNVD Published: 2025-06-13

Description (Chinese)

XWiki Platform是XWiki开源的一套用于创建Web协作应用程序的Wiki平台。 XWiki Platform存在安全漏洞,该漏洞源于用户可创建包含恶意内容的文档,可能导致跨站脚本攻击。

Description (English)

XWiki Platform is an open source of XWiki ’ s Wiki platform for creating a Web collaborative application. There is a security loophole in XWiki Platform, which stems from the fact that the user can create a document containing malicious content, which could lead to a cross-site script attack.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

XWiki

Published

2025-06-13

Last Modified

2026-02-24

References

https://github.com/xwiki/xwiki-platform/commit/55c5d568c4dc4619f37397d00d14dcdeab9c252d https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-j7p2-87q3-44w7 https://jira.xwiki.org/browse/XWIKI-22470 https://access.redhat.com/security/cve/cve-2025-49587

Patch

https://www.xwiki.org/xwiki/bin/view/Download/

Share on: