Access Control Flaw in XWiki Admin Tools by XWiki
CVE-2025-54990

5.3MEDIUM

Key Information:

Vendor

Xwikisas

Vendor
CVE Published:
18 November 2025

What is CVE-2025-54990?

The XWiki Admin Tools suffers from an access control vulnerability that allows users without administrative rights to access AdminTools.SpammedPages. Although the content remains invisible to non-admin users, the mere accessibility of this page poses security risks. This flaw was addressed in version 1.1. To mitigate the issue prior to upgrading, administrators can restrict view rights for the AdminTools space exclusively to members of the XWikiAdminGroup.

Affected Version(s)

application-admintools < 1.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54990 : Access Control Flaw in XWiki Admin Tools by XWiki