CVE-2025-48885

application-urlshortener create shortened URLs for XWiki pages. Versions prior to 1.2.4 are vulnerable to users with view access being able to create arbitrary pages. Any user (even guests) can create these docs, even if they don't exist already. This can enable guest users to denature the structure of wiki pages, by creating 1000's of pages with random name, that then become very difficult to handle by admins. Version 1.2.4 fixes the issue. No known workarounds are available.
CVSS

No CVSS.

Configurations

No configuration.

History

30 May 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-30 19:15

Updated : 2025-06-02 17:32


NVD link : CVE-2025-48885

Mitre link : CVE-2025-48885

CVE.ORG link : CVE-2025-48885


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)