Impact
A path traversal flaw in XWiki Platform’s WebJars API allows a malicious extension, once installed, to write arbitrary files. The flaw can be exploited only after an attacker secures admin privileges on a subwiki and has access to an extension repository to which the attacker can upload a malicious WebJar. When triggered, the attacker could overwrite configuration files or reset the superadmin password, leading to complete compromise of the wiki instance.
Affected Systems
The vulnerability affects XWiki Platform from version 9.6‑rc‑1 up through versions prior to 16.10.17, 17.4.9, 17.10.3, and 18.0.0RC1. Versions 16.10.17, 17.4.9, 17.10.3 and 18.0.0RC1 contain the fix. Products outside the XWiki Platform scope are not impacted.
Risk and Exploitability
With a CVSS score of 5.9, the flaw is considered moderate. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to already have subwiki admin rights and the ability to publish an extension in a configured repository, so the attack surface is limited to environments where those privileges are granted. Nonetheless, because the outcome can overwrite critical configuration files, the risk remains significant in the presence of sufficient privilege.
OpenCVE Enrichment
Github GHSA