External risk intelligence

XWiki Platform REST Search HQL Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-52472

XWiki is a web-based platform typically deployed as a public-facing wiki or collaborative application. As an internet-accessible web service that handles search requests via its API, the vulnerable REST search endpoint is often exposed to the network to support collaborative content management, making it a likely target for remote interaction.

SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the XWiki Platform's REST search functionality could allow unauthorized access to information by exploiting an HQL injection flaw. This issue impacts systems using specific versions of the XWiki Platform and has been addressed in later releases.

  • The platform's search feature can be manipulated.
  • Critical system functions could be compromised.
  • Confirm relevance and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a crafted request to the platform's REST API. This request would target the search functionality, specifically manipulating the `orderField` parameter to inject malicious HQL (Hibernate Query Language) code. If successful, this injection could allow an attacker to manipulate database queries, potentially leading to unauthorized access or modification of sensitive information.

  • Network exposure required.
  • Manipulated search parameter triggers vulnerability.
  • Risk of unauthorized data access and modification.

Live Threat

Current exploitation, exposure, and threat context

The REST search functionality in XWiki Platform could be at risk of HQL injection. This may allow an attacker to manipulate database queries through the `orderField` parameter, potentially affecting the integrity and availability of the wiki's data or underlying system when supported by the advisory.

  • Wiki data and system integrity.
  • Malicious input in the `orderField` parameter.
  • Compromised data or service disruption.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts XWiki Platform deployments, specifically the REST search functionality. The primary responsibility for addressing this issue likely lies with the application owners or platform teams managing XWiki instances, in coordination with the security team for exposure assessment and network teams if external access is confirmed. The immediate first step is to inventory all XWiki deployments, determine their internet-facing status and business criticality, identify the accountable owners, and then prioritize remediation based on risk.

  • Application owners or platform teams should own.
  • Verify XWiki deployment reachability and criticality.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is XWiki Platform?

XWiki Platform is a versatile, open-source software framework used to build collaborative wiki applications and runtime services. Organizations deploy it to manage internal knowledge bases, documentation, or public-facing content sites, leveraging its search and REST API capabilities to help users interact with stored information efficiently.

What does HQL injection mean in CVE-2025-52472?

This vulnerability involves CWE-89, or Improper Neutralization of Special Elements used in an SQL Command. In this context, it specifically affects Hibernate Query Language (HQL), which XWiki uses to communicate with its database. An attacker aims to bypass security controls by injecting malicious commands into the search query, potentially tricking the system into executing unauthorized database operations.

How is this HQL injection triggered?

The flaw is triggered by sending a specially crafted request to the REST search API, specifically targeting the 'orderField' parameter. Because the system inserts this value into the query twice, an attacker must carefully construct the input so the final database command remains syntactically valid despite the manipulation. Requests that do not interact with this specific search parameter do not trigger the bug.

Why should I care about this XWiki vulnerability?

According to Halo Surface Signal, XWiki is frequently deployed as a public-facing service, making its REST search API potentially reachable from the internet. If your instance is exposed to the network, the risk is higher because unauthorized remote actors could attempt to interact with your database. Even internal instances should be reviewed to understand their risk profile.

How do I respond to this vulnerability?

The primary response is to upgrade your XWiki instance to one of the patched versions: 16.10.9, 17.4.2, or 17.5.0. Before upgrading, inventory all your XWiki deployments to identify which are internet-facing or hold critical business data. Since there are no known workarounds, prioritizing these updates is the only effective way to remove the risk.

References