PT-2026-42215 · Xwiki · Xwiki Platform
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
XWiki versions prior to 16.10.17
XWiki versions prior to 17.4.9
XWiki versions prior to 17.10.3
XWiki versions prior to 18.1.0-rc-1
Description
XWiki Platform allows unauthenticated access to read arbitrary server-side configuration files, such as
WEB-INF/xwiki.cfg. This is possible through a Path Traversal issue, where an attacker can use leading slashes in the resource parameter to escape the intended directory. The issue is specifically exploitable via the /bin/ssx/ and /bin/jsx/ endpoints and has been confirmed on Tomcat deployments.Recommendations
Update to version 16.10.17
Update to version 17.4.9
Update to version 17.10.3
Update to version 18.1.0-rc-1
Exploit
Fix
DoS
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xwiki Platform