Home

Description

XWiki is a generic wiki platform. It's possible to execute any SQL query in Oracle by using the function like DBMS_XMLGEN or DBMS_XMLQUERY. The XWiki query validator does not sanitize functions that would be used in a simple select and Hibernate allows using any native function in an HQL query. This vulnerability is fixed in 16.10.2, 16.4.7, and 15.10.16.

PUBLISHED Reserved 2024-12-17 | Published 2025-06-12 | Updated 2026-01-12 | Assigner GitHub_M




CRITICAL: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Product status

>= 1.0, < 15.10.16
affected

>= 16.0.0-rc-1, < 16.4.7
affected

>= 16.5.0-rc-1, < 16.10.2
affected

References

github.com/...atform/security/advisories/GHSA-prwh-7838-xf82

github.com/...ommit/ce855aae38eefd8ee3fc86353d51ac03d6cb7f8d

jira.xwiki.org/browse/XWIKI-22734

cve.org (CVE-2024-56158)

nvd.nist.gov (CVE-2024-56158)

Download JSON