{"id":"CVE-2025-32974","summary":"org.xwiki.platform:xwiki-platform-security-requiredrights-default required rights analysis doesn't consider TextAreas with default content type","details":"XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.8 and from 16.0.0-rc-1 to before 16.2.0, the required rights analysis doesn't consider TextAreas with default content type. When editing a page, XWiki warns since version 15.9 when there is content on the page like a script macro that would gain more rights due to the editing. This analysis doesn't consider certain kinds of properties, allowing a user to put malicious scripts in there that will be executed after a user with script, admin, or programming rights edited the page. Such a malicious script could impact the confidentiality, integrity and availability of the whole XWiki installation. This issue has been patched in versions 15.10.8 and 16.2.0.","aliases":["GHSA-mvgm-3rw2-7j4r"],"modified":"2026-08-12T15:13:27.087374Z","published":"2025-04-30T14:55:01.470Z","database_specific":{"cwe_ids":["CWE-116","CWE-269"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/32xxx/CVE-2025-32974.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-22002"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/32xxx/CVE-2025-32974.json"},{"type":"ADVISORY","url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-mvgm-3rw2-7j4r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-32974"},{"type":"FIX","url":"https://github.com/xwiki/xwiki-platform/commit/153dbfa2ef1a7a0a644fe3f889684c6a8738c5fc"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/xwiki/xwiki-commons","events":[{"introduced":"943b4a6a0a0e2b9b94f6f184e823f82b262ea8d3"},{"fixed":"63e05b1723e99d6914e6be23572cbb16affa6fd1"},{"introduced":"918ea43fe0d277c28efa21a871175b329c75157c"},{"fixed":"d0d232549d26fc58d257ab828387fa9a4c82474d"}],"database_specific":{"cpe":"cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"15.9"},{"fixed":"15.10.8"},{"introduced":"16.0.0"},{"fixed":"16.2.0"}],"source":"CPE_RANGE"}},{"type":"GIT","repo":"https://github.com/xwiki/xwiki-platform","events":[{"introduced":"7a8f9b1236bc9271b607fb92e700377e37f67cf2"},{"fixed":"4524f78640db8d9d09d8706682663a7bed574741"},{"introduced":"3c6f5cf138d8095f63631e554ba448e4b780e162"},{"fixed":"69887c6c1d6aaeeb2690b37a77b3bcdfda7b71cb"},{"fixed":"153dbfa2ef1a7a0a644fe3f889684c6a8738c5fc"}],"database_specific":{"cpe":"cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"15.9"},{"fixed":"15.10.8"},{"introduced":"16.0.0"},{"fixed":"16.2.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-32974.json","vanir_signatures_modified":"2026-08-12T15:13:27Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/xwiki/xwiki-platform/commit/153dbfa2ef1a7a0a644fe3f889684c6a8738c5fc","target":{"file":"xwiki-platform-core/xwiki-platform-security/xwiki-platform-security-requiredrights/xwiki-platform-security-requiredrights-default/src/test/java/org/xwiki/platform/security/requiredrights/internal/analyzer/DefaultObjectRequiredRightAnalyzerTest.java"},"deprecated":false,"digest":{"line_hashes":["226069511102521335188098535328873357559","197060651207309436982539612614645631606","290770070121725405145928573911956084437"],"threshold":0.9},"id":"CVE-2025-32974-4855b73d","signature_type":"Line"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/xwiki/xwiki-platform/commit/153dbfa2ef1a7a0a644fe3f889684c6a8738c5fc","target":{"file":"xwiki-platform-core/xwiki-platform-security/xwiki-platform-security-requiredrights/xwiki-platform-security-requiredrights-default/src/main/java/org/xwiki/platform/security/requiredrights/internal/analyzer/DefaultObjectRequiredRightAnalyzer.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["110952391712989702301648110291469596380","302283329407220475072199310372178795367","126394419629124546362898852734670513670","57754101762947105777884950809867239435","189174533329779968413768079895716020257","321519284673715243330356728053174817847","161247248959686534640251771146995590066","285294932251818390514396102241023547055","284603682172586540150283281786462056235","138551668023294964681285374293979297859","156960560206366507520701486278889321888","87933102183178844154278954968325861605","57452729120454066050503569110316584309","273044645211350846033584871890401335473","163365333947463192760216260292028193514"]},"id":"CVE-2025-32974-511c4880"},{"id":"CVE-2025-32974-9bd43ff9","signature_type":"Function","signature_version":"v1","source":"https://github.com/xwiki/xwiki-platform/commit/153dbfa2ef1a7a0a644fe3f889684c6a8738c5fc","target":{"file":"xwiki-platform-core/xwiki-platform-security/xwiki-platform-security-requiredrights/xwiki-platform-security-requiredrights-default/src/main/java/org/xwiki/platform/security/requiredrights/internal/analyzer/DefaultObjectRequiredRightAnalyzer.java","function":"analyzeTextAreaProperty"},"deprecated":false,"digest":{"function_hash":"180887270903970764166449532531961568395","length":878}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"}]}