CVE-2025-32972: The lesscss script service allows cache clearing without programming right

2.7 CVSS

Description

XWiki is a generic wiki platform. In versions starting from 6.1-milestone-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.8.0-rc-1, the script API of the LESS compiler in XWiki is incorrectly checking for rights when calling the cache cleaning API, making it possible to clean the cache without having programming right. The only impact of this is a slowdown in XWiki execution as the caches are re-filled. As this vulnerability requires script right to exploit, and script right already allows unlimited execution of scripts, the additional impact due to this vulnerability is low. This issue has been patched in versions 15.10.12, 16.4.3, and 16.8.0-rc-1.

Classification

CVE ID: CVE-2025-32972

CVSS Base Severity: LOW

CVSS Base Score: 2.7

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L

Problem Types

CWE-285: Improper Authorization

Affected Products

Vendor: xwiki

Product: xwiki-platform

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.07% (probability of being exploited)

EPSS Percentile: 22.31% (scored less or equal to compared to others)

EPSS Date: 2025-05-29 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-32972
https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-rp38-24m3-rx87
https://github.com/xwiki/xwiki-platform/commit/91752122d8782f171f8728004a57bdaefc34253e
https://jira.xwiki.org/browse/XWIKI-22462

Timeline