Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-v7r8-8p5c-h4xw: XWiki AdminTools application doesn't set permissions on the AdminTools space

Impact

Users without admin rights have access to AdminTools.SpammedPages.

Details

View rights are not restricted only to admin users for AdminTools.SpammedPages. While no data is visible to non admin users, the page is still accessible.

Workarounds

Set the view rights for the AdminTools space to be only available for the XWikiAdminGroup.

ghsa
#git#java#maven
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2025-54990

XWiki AdminTools application doesn’t set permissions on the AdminTools space

Package

maven com.xwiki.admintools:application-admintools (Maven)

Impact

Users without admin rights have access to AdminTools.SpammedPages.

Details

View rights are not restricted only to admin users for AdminTools.SpammedPages. While no data is visible to non admin users, the page is still accessible.

Workarounds

Set the view rights for the AdminTools space to be only available for the XWikiAdminGroup.

References

  • GHSA-v7r8-8p5c-h4xw

Published to the GitHub Advisory Database

Nov 18, 2025

Last updated

Nov 18, 2025

ghsa: Latest News

GHSA-7xcv-9j6c-2fmc: Modular Max Serve has Unsafe Deserialization vulnerability