Configuration File Exposure Vulnerability in XWiki Platform by XWiki
CVE-2025-55747
9.3CRITICAL
What is CVE-2025-55747?
The XWiki Platform version 6.1-milestone-2 through 16.10.6 contains a vulnerability that allows unauthorized access to sensitive configuration files via the webjars API. This exposure could potentially lead to the disclosure of sensitive information, including authentication credentials and system configurations, posing a significant security risk for applications built on the platform. The issue has been addressed in version 16.10.7, which is recommended for all users to mitigate this vulnerability.
Affected Version(s)
xwiki-platform >= 6.1-milestone-2, < 16.10.7