PT-2022-16132 · Xwiki · Xwiki Platform

Tmortagne

·

Published

2022-02-09

·

Updated

2022-02-15

·

CVE-2022-23619

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions XWiki Platform versions prior to 12.10.9 XWiki Platform versions prior to 13.4.1 XWiki Platform versions prior to 13.6RC1
Description The issue allows an attacker to guess if a user has an account on the wiki by using the "Forgot your password" form, even if the wiki is closed to guest users. There are no known workarounds for this issue.
Recommendations For versions prior to 12.10.9, update to version 12.10.9 or later. For versions prior to 13.4.1, update to version 13.4.1 or later. For versions prior to 13.6RC1, update to version 13.6RC1 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23619
GHSA-35FG-HJCR-J65F

Affected Products

Xwiki Platform