Логотип exploitDog
bind:CVE-2021-32730
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-32730

Количество 2

Количество 2

nvd логотип

CVE-2021-32730

больше 4 лет назад

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A cross-site request forgery vulnerability exists in versions prior to 12.10.5, and in versions 13.0 through 13.1. It's possible for forge an URL that, when accessed by an admin, will reset the password of any user in XWiki. The problem has been patched in XWiki 12.10.5 and 13.2RC1. As a workaround, it is possible to apply the patch manually by modifying the `register_macros.vm` template.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-v9j2-q4q5-cxh4

больше 4 лет назад

No CSRF protection on the password change form

CVSS3: 5.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-32730

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A cross-site request forgery vulnerability exists in versions prior to 12.10.5, and in versions 13.0 through 13.1. It's possible for forge an URL that, when accessed by an admin, will reset the password of any user in XWiki. The problem has been patched in XWiki 12.10.5 and 13.2RC1. As a workaround, it is possible to apply the patch manually by modifying the `register_macros.vm` template.

CVSS3: 5.7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-v9j2-q4q5-cxh4

No CSRF protection on the password change form

CVSS3: 5.7
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу