PT-2021-19891 · Xwiki · Xwiki Platform
Pierrick Vuillemin
·
Published
2021-07-01
·
Updated
2021-07-09
·
CVE-2021-32730
CVSS v3.1
5.7
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
XWiki Platform versions prior to 12.10.5
XWiki Platform versions 13.0 through 13.1
Description
A cross-site request forgery issue exists, allowing an attacker to forge a URL that, when accessed by an admin, will reset the password of any user in XWiki.
Recommendations
For versions prior to 12.10.5, update to version 12.10.5 or later.
For versions 13.0 through 13.1, update to version 13.2RC1 or later.
As a temporary workaround, consider applying the patch manually by modifying the
register macros.vm template.Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xwiki Platform