PT-2021-19892 · Xwiki · Xwiki
Simon Urli
·
Published
2021-07-01
·
Updated
2022-10-25
·
CVE-2021-32731
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
XWiki Platform versions 13.1RC1 through 13.1
Description
The reset password form reveals the email address of users just by giving their username. The problem has been patched on XWiki 13.2RC1.
Recommendations
For versions 13.1RC1 through 13.1, manually modify the
resetpasswordinline.vm to perform the changes made to mitigate the vulnerability.
Update to XWiki 13.2RC1 or later to resolve the issue.Fix
Information Disclosure
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xwiki