CVE-2025-24893 | xwiki-platform up to 15.10.10/16.4.0 eval injection (GHSA-rr6p-3pfg-562j / EUVD-2025-4562)
A vulnerability classified as critical was found in xwiki-platform up to 15.10.10/16.4.0. Impacted is an unknown function of the file /xwiki/bin/get/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7Dprintln%28"Hello%20from"%20%2B%20"%20search%20text%3A"%20%2B%20%2823%20%2B%2019%29%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D%20. Executing manipulation can lead to improper neutralization of directives in dynamically evaluated code.
This vulnerability is tracked as CVE-2025-24893. The attack can be launched remotely. Moreover, an exploit is present.
Upgrading the affected component is advised.