A detailed walkthrough of exploiting a Linux machine running XWiki and NetData. The attack chain begins with exploiting CVE-2025-24893, an unauthenticated Groovy script injection vulnerability in XWiki's Solr search, to achieve remote code execution. After gaining initial access, database credentials are extracted from XWiki's

23m read timeFrom 0xdf.gitlab.io
Post cover image
Table of contents
Box InfoReconShell as xwikiShell as oliver on EditorShell as rootBeyond Root

Sort: