CVE-2025-66472: 
Java vulnerability analysis and mitigation

Overview

CVE-2025-66472 is a reflected Cross-Site Scripting (XSS) vulnerability in XWiki, specifically in the xredirect parameter of the DeleteApplication feature. An unauthenticated attacker can craft a malicious URL that, when visited by a victim who clicks the "No" button on a deletion confirmation dialog, executes attacker-supplied JavaScript in the victim's browser. The vulnerability affects XWiki versions 6.2-milestone-1 through 16.10.9 and 17.0.0-rc-1 through 17.4.1. It was disclosed on December 10, 2025, with a CVSS v3.1 score of 6.1 (Medium) and a CVSS v4.0 score of 6.5 (Medium) (Github Advisory, XWiki Security Advisory).

Technical details

The root cause is improper neutralization of script-related HTML tags in a web page (CWE-79, CWE-80). The xredirect URL parameter used in XWiki's deletion confirmation templates (macros.vm in both xwiki-platform-flamingo-skin-resources and xwiki-platform-web-templates) was rendered without proper sanitization, allowing attacker-controlled content to be injected into the HTML of the confirmation page. The fix (commit cb578b1) restructured the confirmation dialog to use the xredirect parameter only in its intended context — as a redirect URL — rather than rendering it directly as HTML content, eliminating the injection point (XWiki Security Advisory, Patch Commit).

Impact

When exploited against a victim with admin or programming rights, this vulnerability effectively enables remote code execution on the XWiki installation, as XWiki's scripting engine allows privileged users to execute arbitrary server-side code. An attacker could leverage this to modify system configurations, create unauthorized user accounts, exfiltrate sensitive wiki content, or fully compromise the XWiki instance. Even against lower-privileged users, the XSS can be used to steal session tokens or perform unauthorized actions within the victim's session (Github Advisory).

Exploitability

A proof-of-concept exploit reference is available via the XWiki Jira issue tracker (XWIKI-23244), and a Nuclei detection template has been developed and merged into the ProjectDiscovery nuclei-templates repository. There is no confirmed evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.039% (0.095% per GitHub Advisory), indicating low but non-negligible exploitation probability. The vulnerability is not listed in the CISA KEV catalog. No specific threat actor attribution has been reported (Github Advisory, XWiki Jira).

Exploitation steps

  1. Reconnaissance: Identify internet-facing XWiki installations running versions between 6.2-milestone-1 and 16.10.9, or 17.0.0-rc-1 and 17.4.1, using tools like Shodan or Censys, or by checking the XWiki version page.
  2. Craft malicious URL: Construct a URL targeting the XWiki DeleteApplication endpoint with a malicious JavaScript payload injected into the xredirect parameter, e.g., https://target-xwiki.example.com/xwiki/bin/delete/App/WebHome?xredirect=javascript:alert(document.cookie) or a more complex payload encoded to bypass basic filters.
  3. Social engineering: Send the crafted URL to a target victim known or suspected to have admin or programming rights on the XWiki instance, via phishing email, chat message, or other communication channel.
  4. Trigger execution: When the victim navigates to the URL, they are presented with a deletion confirmation dialog. When they click the "No" button, the attacker-supplied script executes in the victim's browser session.
  5. Achieve objective: With admin/programming rights, the executed script can invoke XWiki's scripting API to run arbitrary server-side Groovy or Velocity code, create new admin accounts, exfiltrate data, or establish persistence (XWiki Security Advisory, XWiki Jira).

Indicators of compromise

  • Network: HTTP requests to XWiki deletion endpoints (e.g., /xwiki/bin/delete/) containing suspicious xredirect parameter values with JavaScript schemes (javascript:), encoded script tags, or unusual URL-encoded characters.
  • Logs: XWiki access logs showing GET/POST requests to delete confirmation pages with anomalous xredirect parameter values; repeated requests from external referrers or unfamiliar IP addresses targeting deletion endpoints.
  • Application Behavior: Unexpected creation of new admin or privileged user accounts; unauthorized modifications to wiki pages, scripts, or configuration; unusual Groovy/Velocity script execution events in XWiki logs.
  • Browser/Session: Victim session tokens appearing in attacker-controlled server logs (indicating cookie theft); unexpected API calls made under admin credentials from unusual IP addresses or user agents.

Mitigation and workarounds

XWiki has released patches in versions 16.10.10, 17.4.2, and 17.5.0. Administrators should upgrade to one of these versions as the primary remediation. For those unable to upgrade immediately, the patch can be manually applied to the affected Velocity templates (macros.vm in both xwiki-platform-flamingo-skin-resources and xwiki-platform-web-templates) present in the WAR file, followed by a restart of XWiki. Additionally, restricting admin and programming rights to only essential users reduces the potential impact of exploitation (Github Advisory, Patch Commit).

Community reactions

The vulnerability was reported by security researcher 4rdr and published by XWiki maintainer michitux on December 10, 2025. A Nuclei detection template was subsequently contributed to the ProjectDiscovery nuclei-templates repository, indicating community interest in automated detection. Social media activity on Bluesky referenced the CVE, and it was picked up by standard vulnerability aggregators. No major vendor statements beyond the XWiki advisory or significant media coverage have been identified (Github Advisory).

Additional resources


Source: This report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103922CRITICAL9.3
  • JavaScript logoJavaScript
  • com.capacitorjs:core
NoYesOct 01, 2026
CVE-2026-61741CRITICAL9.3
  • Java logoJava
  • org.http4s:http4s-scala-xml_2.12
NoYesSep 24, 2026
CVE-2026-54049HIGH8.7
  • Java logoJava
  • org.sakaiproject.rubrics:rubrics-impl
NoNoOct 01, 2026
CVE-2026-100660HIGH8.7
  • Java logoJava
  • io.netty:netty-codec-http3
NoNoSep 26, 2026
CVE-2026-61586HIGH8.2
  • Java logoJava
  • eu.copernik:copernik-xml-factory
NoYesOct 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management