Headline
GHSA-8c52-x9w7-vc95: XWiki view file macro: User can view content of office file without view rights on the attachment
Summary
A user with no view rights on a page may see the content of an office attachment displayed with the view file macro.
Details
If on a public page is displayed an office attachment from a restricted page, a user with no view rights on the restricted page can view the attachment content, no matter the display type used.
PoC
- Install and activate the Pro Macros application
- Create a page and limit the view rights for a test user
- Add an attachment to the restricted page
- Create a new public page
- Add the view file macro and select the attachment from the restricted page using any display type
- Login as the test user with restricted view rights
- The user will see the content despite having no view rights
Workarounds
None
Impact
Private data can be leaked if a user knows the reference to an attachment and has edit rights on a page.
- GitHub Advisory Database
- GitHub Reviewed
- CVE-2025-65089
XWiki view file macro: User can view content of office file without view rights on the attachment
Package
maven com.xwiki.pro:xwiki-pro-macros-ui (Maven)
Affected versions
<= 1.26.20
Summary
A user with no view rights on a page may see the content of an office attachment displayed with the view file macro.
Details
If on a public page is displayed an office attachment from a restricted page, a user with no view rights on the restricted page can view the attachment content, no matter the display type used.
PoC
- Install and activate the Pro Macros application
- Create a page and limit the view rights for a test user
- Add an attachment to the restricted page
- Create a new public page
- Add the view file macro and select the attachment from the restricted page using any display type
- Login as the test user with restricted view rights
- The user will see the content despite having no view rights
Workarounds
None
Impact
Private data can be leaked if a user knows the reference to an attachment and has edit rights on a page.
References
- GHSA-8c52-x9w7-vc95
Published to the GitHub Advisory Database
Nov 18, 2025