{"id":"CVE-2025-32970","aliases":["GHSA-pjhg-9wr9-rj96"],"url":"https://o3.security/vulnerability/CVE-2025-32970","summary":"org.xwiki.platform:xwiki-platform-wysiwyg-api Open Redirect vulnerability","details":"### Impact\n\nAn open redirect vulnerability in the HTML conversion request filter allows attackers to construct URLs on an XWiki instance that redirect to any URL. To reproduce, open `<xwiki-host>/xwiki/bin/view/Main/?foo=bar&foo_syntax=invalid&RequiresHTMLConversion=foo&xerror=https://www.example.com/` where `<xwiki-host>` is the URL of your XWiki installation.\n\n### Patches\nThis bug has been fixed in XWiki 15.10.13, 16.4.4 and 16.8.0 by validating the domain of the redirect URL against the configured safe domains and the current request's domain.\n\n### Workarounds\nA web application firewall could be configured to reject requests with the `xerror` parameter as from our analysis this parameter isn't used anymore. For requests with the `RequiresHTMLConversion` parameter set, the referrer URL should be checked if it points to the XWiki installation. Apart from that, we're not aware of any workarounds.","published":"2025-04-30T14:54:52.008Z","modified":"2026-08-12T15:13:27.340526Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.00584,"percentile":0.46415,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-wysiwyg-api","fixedVersion":"15.10.13"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-wysiwyg-api","fixedVersion":"16.4.4"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-wysiwyg-api","fixedVersion":"16.8.0"}],"fix":{"url":"https://github.com/xwiki/xwiki-platform/commit/6dab7909f45deb00efd36a0cd47788e95ad64802","label":"xwiki/xwiki-platform@6dab790"},"references":[{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-22487"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/32xxx/CVE-2025-32970.json"},{"type":"ADVISORY","url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-pjhg-9wr9-rj96"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-32970"},{"type":"FIX","url":"https://github.com/xwiki/xwiki-platform/commit/6dab7909f45deb00efd36a0cd47788e95ad64802"},{"type":"PACKAGE","url":"https://github.com/xwiki/xwiki-platform"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T15:13:27.340526Z"}}