XWiki view file macro: User can view content of office file without view rights on the attachment
Vulnerability Description
XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to version 1.27.0, a user with no view rights on a page may see the content of an office attachment displayed with the view file macro. This issue has been patched in version 1.27.0.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-65089
Credits & Attribution
No credits recorded in the NVD database.
More from xwikisas
View All →Affected Vendor
xwikisas
View all reports →