CVE-2025-27603

XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. A user that doesn't have programming rights can execute arbitrary code due to an unescaped translation when creating a page using the Migration Page template. This vulnerability is fixed in 1.2.0.
Configurations

No configuration.

History

07 Mar 2025, 18:15

Type Values Removed Values Added
References () https://github.com/xwikisas/application-confluence-migrator-pro/security/advisories/GHSA-6qvp-39mm-95v8 - () https://github.com/xwikisas/application-confluence-migrator-pro/security/advisories/GHSA-6qvp-39mm-95v8 -

07 Mar 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-07 16:15

Updated : 2025-03-07 18:15


NVD link : CVE-2025-27603

Mitre link : CVE-2025-27603

CVE.ORG link : CVE-2025-27603


JSON object : View

Products Affected

No product.

CWE
CWE-95

Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')