目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2025-24893— XWiki Platform 安全漏洞

一分钟漏洞结论

影响对象
xwiki xwiki-platform
利用判断
已确认在野利用,应立即处置
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

XWiki Platform是XWiki开源的一套用于创建Web协作应用程序的Wiki平台。 XWiki Platform存在安全漏洞,该漏洞源于任何来宾用户都可以通过对SolrSearch的请求,造成远程代码执行。

CVSS 9.8 · Critical KEV EPSS 99.86% · P100
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2025-24893 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Remote code execution as guest via SolrSearchMacros request in xwiki
来源: CVE Program / CVE List V5
Vulnerability Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity and availability of the whole XWiki installation. To reproduce on an instance, without being logged in, go to `<host>/xwiki/bin/get/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7Dprintln%28"Hello%20from"%20%2B%20"%20search%20text%3A"%20%2B%20%2823%20%2B%2019%29%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D%20`. If there is an output, and the title of the RSS feed contains `Hello from search text:42`, then the instance is vulnerable. This vulnerability has been patched in XWiki 15.10.11, 16.4.1 and 16.5.0RC1. Users are advised to upgrade. Users unable to upgrade may edit `Main.SolrSearchMacros` in `SolrSearchMacros.xml` on line 955 to match the `rawResponse` macro in `macros.vm#L2824` with a content type of `application/xml`, instead of simply outputting the content of the feed.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
动态执行代码中指令转义处理不恰当(Eval注入)
来源: CVE Program / CVE List V5
Vulnerability Title
XWiki Platform 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
XWiki Platform是XWiki开源的一套用于创建Web协作应用程序的Wiki平台。 XWiki Platform存在安全漏洞,该漏洞源于任何来宾用户都可以通过对SolrSearch的请求,造成远程代码执行。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

神龙十问 — AI 深度分析

十问解析:根本原因、利用方式、修复建议、紧迫性。摘要免费,完整版需登录。

受影响产品

厂商 产品 影响版本 CPE 订阅
xwiki xwiki-platform >= 5.3-milestone-2, < 15.10.11 -

二、漏洞 CVE-2025-24893 的公开POC

# POC 描述 源链接 神龙链接
1 XWiki Remote Code Execution (CVE-2025-24893) PoC https://github.com/sug4r-wr41th/CVE-2025-24893 POC详情
2 XWiki SolrSearchMacros 远程代码执行漏洞PoC(CVE-2025-24893) https://github.com/iSee857/CVE-2025-24893-PoC POC详情
3 Any guest can perform arbitrary remote code execution through a request to SolrSearch. This impacts the confidentiality, integrity, and availability of the whole XWiki installation. This vulnerability has been patched in XWiki 15.10.11, 16.4.1, and 16.5.0RC1. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-24893.yaml POC详情
4 None https://github.com/Artemir7/CVE-2025-24893-EXP POC详情
5 None https://github.com/nopgadget/CVE-2025-24893 POC详情
6 This is a small script for the rce vulnerability for CVE-2025-24893. It supports basic input/output https://github.com/Kai7788/CVE-2025-24893-RCE-PoC POC详情
7 this is a poc for the CVE-2025-24893 https://github.com/AliElKhatteb/CVE-2024-32019-POC POC详情
8 None https://github.com/dhiaZnaidi/CVE-2025-24893-PoC POC详情
9 Modified exploit for CVE-2025-24893 https://github.com/hackersonsteroids/cve-2025-24893 POC详情
10 PoC exploits CVE-2025-24893 , a remote code execution (RCE) vulnerability in XWiki caused by improper sandboxing in Groovy macros rendered asynchronously. It allows arbitrary command execution through injection into RSS-based SolrSearch endpoints. https://github.com/Infinit3i/CVE-2025-24893 POC详情
11 PoC for CVE-2025-24893: XWiki' Remote Code Execution exploit for versions prior to 15.10.11, 16.4.1 and 16.5.0RC1. https://github.com/gunzf0x/CVE-2025-24893 POC详情
12 CVE-2025-24893 is a critical unauthenticated remote code execution vulnerability in XWiki (versions < 15.10.11, 16.4.1, 16.5.0RC1) caused by improper handling of Groovy expressions in the SolrSearch macro. https://github.com/dollarboysushil/CVE-2025-24893-XWiki-Unauthenticated-RCE-Exploit-POC POC详情
13 PoC | XWiki Platform 15.10.10 - Remote Code Execution https://github.com/zs1n/CVE-2025-24893 POC详情
14 Proof-of-Concept exploit for CVE-2025-24893, an unauthenticated Remote Code Execution (RCE) vulnerability in XWiki. Exploits a template injection flaw in the SolrSearch endpoint via Groovy script execution. https://github.com/investigato/cve-2025-24893-poc POC详情
15 PoC for CVE-2025-24893 https://github.com/570RMBR3AK3R/xwiki-cve-2025-24893-poc POC详情
16 CVE-2025-24893 is a critical unauthenticated remote code execution (RCE) vulnerability in XWiki, a popular open-source enterprise wiki platform. https://github.com/IIIeJlyXaKapToIIIKu/CVE-2025-24893-XWiki-unauthenticated-RCE-via-SolrSearch POC详情
17 Bash POC script for RCE vulnerability in XWiki Platform https://github.com/mah4nzfr/CVE-2025-24893 POC详情
18 None https://github.com/Th3Gl0w/CVE-2025-24893-POC POC详情
19 This vulnerability could allow a malicious user to execute remote code by sending appropriately crafted requests to the default search engine SolrSearch https://github.com/Hex00-0x4/CVE-2025-24893-XWiki-RCE POC详情
20 POC https://github.com/The-Red-Serpent/CVE-2025-24893 POC详情
21 XWiki 15.10.11, 16.4.1 and 16.5.0RC1 Unauthenticated Remote code execution POC https://github.com/alaxar/CVE-2025-24893 POC详情
22 POC exploit for CVE-2025-24893 https://github.com/D3Ext/CVE-2025-24893 POC详情
23 A POC for CVE-2025-24893 written in python https://github.com/Retro023/CVE-2025-24893-POC POC详情
24 PoC exploit for XWiki Remote Code Execution Vulnerability (CVE-2025-24893) https://github.com/CMassa/CVE-2025-24893 POC详情
25 Some poorly crafted exploit scripts https://github.com/x0da6h/POC-for-CVE-2025-24893 POC详情
26 A critical remote code execution (RCE) vulnerability (CVE‑2025‑24893) exists in the XWiki Platform, specifically in the SolrSearch RSS feed endpoint. https://github.com/ibadovulfat/CVE-2025-24893_HackTheBox-Editor-Writeup POC详情
27 Unauth RCE PoC for XWiki SolrSearch (CVE-2025-24893). Command exec + reverse shell. Built during process of pwning HTB “Editor” https://github.com/torjan0/xwiki_solrsearch-rce-exploit POC详情
28 Reverse Shell Payload for CVE-2025-24893 https://github.com/AzureADTrent/CVE-2025-24893-Reverse-Shell POC详情
29 None https://github.com/b0ySie7e/CVE-2025-24893 POC详情
30 None https://github.com/andwati/CVE-2025-24893 POC详情
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-24893 的情报信息

请登录查看更多情报信息。

CVE-2025-24893 补丁与修复 (4)

CVE-2025-24893 厂商安全公告 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2025-24893

匿名用户
2026-01-15 06:08:49

Zaproxy alias impedit expedita quisquam pariatur exercitationem. Nemo rerum eveniet dolores rem quia dignissimos.


发表评论