A critical vulnerability, CVE-2025-24893, has been identified in XWiki Platform. This vulnerability allows unauthenticated remote code execution (RCE) via crafted requests to the SolrSearch endpoint, embedding Groovy script execution within the search query parameters. It impacts the confidentiality, integrity, and availability. This issue has been patched in XWiki 15.10.11, 16.4.1, and 16.5.0RC1, and users are strongly advised to upgrade. The IONIX research team developed and tested an exploit simulation on relevant assets to verify the vulnerability’s impact and assess potential exposure. The findings are detailed in this post.
References:

