SQL Injection Vulnerability in XWiki Platform by XWiki
CVE-2025-32429
9.3CRITICAL
What is CVE-2025-32429?
An SQL injection vulnerability exists in the XWiki Platform, specifically in the handling of the 'sort' parameter within the getdeleteddocuments.vm file. This flaw allows an attacker to inject arbitrary SQL code, which could lead to unauthorized data access and manipulation. It affects versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2 but is mitigated in versions 16.10.6 and 17.3.0-rc-1. Users are encouraged to upgrade to these revised versions to safeguard against potential exploits.
Affected Version(s)
xwiki-platform >= 9.4-rc-1, < 16.10.6 < 9.4-rc-1, 16.10.6
xwiki-platform >= 17.0.0-rc-1, < 17.3.0-rc-1 < 17.0.0-rc-1, 17.3.0-rc-1