XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SSTI) in the Administration interface, specifically within the HTTP Meta Info field of the Global Preferences Presentation section. An authenticated administrator can inject crafted Apache Velocity template code, which is rendered on the server side without proper validation or sandboxing. This enables the execution of arbitrary template logic, which may expose internal server information or, in specific configurations, lead to further exploitation such as remote code execution or sensitive data leakage. The vulnerability resides in improper handling of dynamic template rendering within user-supplied configuration fields.
History

Thu, 21 Aug 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Xwiki
Xwiki xwiki
Vendors & Products Xwiki
Xwiki xwiki

Wed, 20 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
CWE-94
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 20 Aug 2025 15:00:00 +0000

Type Values Removed Values Added
Description XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SSTI) in the Administration interface, specifically within the HTTP Meta Info field of the Global Preferences Presentation section. An authenticated administrator can inject crafted Apache Velocity template code, which is rendered on the server side without proper validation or sandboxing. This enables the execution of arbitrary template logic, which may expose internal server information or, in specific configurations, lead to further exploitation such as remote code execution or sensitive data leakage. The vulnerability resides in improper handling of dynamic template rendering within user-supplied configuration fields.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-08-20T00:00:00.000Z

Updated: 2025-08-20T15:43:26.008Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-51991

cve-icon Vulnrichment

Updated: 2025-08-20T15:42:22.098Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-20T15:15:33.327

Modified: 2025-08-22T18:09:17.710

Link: CVE-2025-51991

cve-icon Redhat

No data.