Access Control Flaw in XWiki Admin Tools by XWiki
CVE-2025-54990
5.3MEDIUM
What is CVE-2025-54990?
The XWiki Admin Tools suffers from an access control vulnerability that allows users without administrative rights to access AdminTools.SpammedPages. Although the content remains invisible to non-admin users, the mere accessibility of this page poses security risks. This flaw was addressed in version 1.1. To mitigate the issue prior to upgrading, administrators can restrict view rights for the AdminTools space exclusively to members of the XWikiAdminGroup.
Affected Version(s)
application-admintools < 1.1
