Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v7r8-8p5c-h4xw | XWiki AdminTools application doesn't set permissions on the AdminTools space |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 21 Nov 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xwiki
Xwiki admin Tools |
|
| Vendors & Products |
Xwiki
Xwiki admin Tools |
Wed, 19 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XWiki AdminTools integrates administrative tools for managing a running XWiki instance. Prior to version 1.1, users without admin rights have access to AdminTools.SpammedPages. View rights are not restricted only to admin users for AdminTools.SpammedPages. While no data is visible to non admin users, the page is still accessible. This issue has been patched in version 1.1. A workaround involves setting the view rights for the AdminTools space to be only available for the XWikiAdminGroup. | |
| Title | XWiki AdminTools application doesn't set permissions on the AdminTools space | |
| Weaknesses | CWE-276 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-19T21:03:14.756Z
Reserved: 2025-08-04T17:34:24.420Z
Link: CVE-2025-54990
Updated: 2025-11-19T21:03:09.990Z
Status : Awaiting Analysis
Published: 2025-11-18T23:15:48.513
Modified: 2025-11-19T19:14:59.327
Link: CVE-2025-54990
No data.
OpenCVE Enrichment
Updated: 2025-11-21T09:16:15Z
Github GHSA