PT-2021-19891 · Xwiki · Xwiki Platform

Pierrick Vuillemin

·

Published

2021-07-01

·

Updated

2021-07-09

·

CVE-2021-32730

CVSS v3.1

5.7

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions XWiki Platform versions prior to 12.10.5 XWiki Platform versions 13.0 through 13.1
Description A cross-site request forgery issue exists, allowing an attacker to forge a URL that, when accessed by an admin, will reset the password of any user in XWiki.
Recommendations For versions prior to 12.10.5, update to version 12.10.5 or later. For versions 13.0 through 13.1, update to version 13.2RC1 or later. As a temporary workaround, consider applying the patch manually by modifying the register macros.vm template.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32730
GHSA-V9J2-Q4Q5-CXH4

Affected Products

Xwiki Platform