XWiki
Discovery
# XWiki default ports
# 8080 - Jetty (common)
# 80/443 - behind reverse proxy
# Nmap fingerprint
nmap -sC -sV TARGET -p 8080
# http-title: XWiki - Main - Intro
# http-server-header: Jetty(10.0.20)
# robots.txt entries
/xwiki/bin/viewattachrev/
/xwiki/bin/viewrev/
/xwiki/bin/edit/
/xwiki/bin/save/
/xwiki/bin/delete/CVE-2025-24893 - Unauthenticated RCE via Groovy Injection
Detection
Exploitation
Payload Structure
Reverse Shell
Post-Exploitation
Configuration Files
Extracting Database Credentials
Database Access
Password Storage
Credential Reuse
XWiki Paths Reference
Path
Description
Last updated