Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-7796 | com.xwiki.confluencepro:application-confluence-migrator-pro-ui Remote Code Execution via unescaped translations |
Github GHSA |
GHSA-6qvp-39mm-95v8 | com.xwiki.confluencepro:application-confluence-migrator-pro-ui Remote Code Execution via unescaped translations |
Fri, 07 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. A user that doesn't have programming rights can execute arbitrary code due to an unescaped translation when creating a page using the Migration Page template. This vulnerability is fixed in 1.2.0. | |
| Title | XWiki Confluence Migrator Pro allows Remote Code Execution via unescaped translations | |
| Weaknesses | CWE-95 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-07T17:57:36.804Z
Reserved: 2025-03-03T15:10:34.078Z
Link: CVE-2025-27603
Updated: 2025-03-07T17:57:28.926Z
Status : Deferred
Published: 2025-03-07T16:15:40.037
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-27603
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA