{"id":"GHSA-mvgm-3rw2-7j4r","summary":"org.xwiki.platform:xwiki-platform-security-requiredrights-default required rights analysis doesn't consider TextAreas with default content type","details":"### Impact\nWhen editing a page, XWiki warns since version 15.9 when there is content on the page like a script macro that would gain more rights due to the editing. This analysis doesn't consider certain kinds of properties, allowing a user to put malicious scripts in there that will be executed after a user with script, admin, or programming rights edited the page. Such a malicious script could impact the confidentiality, integrity and availability of the whole XWiki installation.\n\nTo reproduce, as a user without script right, create a class with a `TextArea` property, create page with an object of that class and a Velocity macro in its content. Then, as an admin, try editing that page. Normally, there should be a warning but in vulnerable versions of XWiki, there is no warning.\n\n### Patches\nThis vulnerability has been patched in XWiki 15.10.8 and 16.2.0.\n\n### Workarounds\nWe're not aware of any workarounds apart from not editing pages that might have been edited by untrusted users as a user with script rights, e.g., by using separate user accounts for admin and non-admin tasks.","aliases":["CVE-2025-32974"],"modified":"2025-04-30T17:29:34Z","published":"2025-04-29T14:05:54Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2025-04-29T14:05:54Z","nvd_published_at":"2025-04-30T15:16:01Z","cwe_ids":["CWE-116","CWE-269"]},"references":[{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-mvgm-3rw2-7j4r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-32974"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/commit/153dbfa2ef1a7a0a644fe3f889684c6a8738c5fc"},{"type":"PACKAGE","url":"https://github.com/xwiki/xwiki-platform"},{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-22002"}],"affected":[{"package":{"name":"org.xwiki.platform:xwiki-platform-security-requiredrights-default","ecosystem":"Maven","purl":"pkg:maven/org.xwiki.platform/xwiki-platform-security-requiredrights-default"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"15.9-rc-1"},{"fixed":"15.10.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-mvgm-3rw2-7j4r/GHSA-mvgm-3rw2-7j4r.json"}},{"package":{"name":"org.xwiki.platform:xwiki-platform-security-requiredrights-default","ecosystem":"Maven","purl":"pkg:maven/org.xwiki.platform/xwiki-platform-security-requiredrights-default"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"16.0.0-rc-1"},{"fixed":"16.2.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-mvgm-3rw2-7j4r/GHSA-mvgm-3rw2-7j4r.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"}]}