Описание
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Between (and including) versions 13.1RC1 and 13.1, the reset password form reveals the email address of users just by giving their username. The problem has been patched on XWiki 13.2RC1. As a workaround, it is possible to manually modify the resetpasswordinline.vm to perform the changes made to mitigate the vulnerability.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
- Issue TrackingPatchVendor Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Issue TrackingPatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:xwiki:xwiki:13.1:-:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:13.1:rc1:*:*:*:*:*:*
EPSS
Процентиль: 25%
0.00087
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200
CWE-200
Связанные уязвимости
CVSS3: 5.3
github
больше 4 лет назад
The reset password form reveal users email address
EPSS
Процентиль: 25%
0.00087
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200
CWE-200