PT-2022-16132 · Xwiki · Xwiki Platform
Tmortagne
·
Published
2022-02-09
·
Updated
2022-02-15
·
CVE-2022-23619
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
XWiki Platform versions prior to 12.10.9
XWiki Platform versions prior to 13.4.1
XWiki Platform versions prior to 13.6RC1
Description
The issue allows an attacker to guess if a user has an account on the wiki by using the "Forgot your password" form, even if the wiki is closed to guest users. There are no known workarounds for this issue.
Recommendations
For versions prior to 12.10.9, update to version 12.10.9 or later.
For versions prior to 13.4.1, update to version 13.4.1 or later.
For versions prior to 13.6RC1, update to version 13.6RC1 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xwiki Platform