PT-2021-19892 · Xwiki · Xwiki

Simon Urli

·

Published

2021-07-01

·

Updated

2022-10-25

·

CVE-2021-32731

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions XWiki Platform versions 13.1RC1 through 13.1
Description The reset password form reveals the email address of users just by giving their username. The problem has been patched on XWiki 13.2RC1.
Recommendations For versions 13.1RC1 through 13.1, manually modify the resetpasswordinline.vm to perform the changes made to mitigate the vulnerability. Update to XWiki 13.2RC1 or later to resolve the issue.

Fix

Information Disclosure

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32731
GHSA-H4M4-PGP4-WHGM

Affected Products

Xwiki