• Register
    • Help

    striker  0 Items
    Currently Supporting
    • Home
    • News
      • VaultWiki News
      • Visit the Wiki
    • Forum
    • Wiki
    • Support
    • What's New?
    • Buy Now
    • Manual
    • 
    • Home
    • VaultWiki Security Update: Everything Affected

    1. Welcome to VaultWiki.org, home of the wiki add-on for vBulletin and XenForo!

      VaultWiki allows your existing forum users to collaborate on creating and managing a site's content pages. VaultWiki is a fully-featured and fully-supported wiki solution for vBulletin and XenForo.

      The VaultWiki Team encourages you to join our community of forum administrators and check out VaultWiki for yourself.

    • VaultWiki Security Update: Everything Affected

      by
      pegasus
      • View Profile
      • View Forum Posts
      • View Blog Entries
      • Visit Homepage
      • View Articles
      Published on October 14, 2014 12:11 PM
      2 Comments Comments
      This past weekend, while investigating a minor bug, our development team discovered a serious security vulnerability in VaultWiki's FILE BB-Code.

      We immediately patched the issue, and have released Patch Level releases for Release Candidates in the VaultWiki 4.x series:
      • 4.0.0 RC 3 Patch Level 1
      • 4.0.0 RC 2 Patch Level 1
      • 4.0.0 RC 1 Patch Level 1


      We highly recommend that all users running VaultWiki in a production environment upgrade to a patched release as soon as possible. Note that because the FILE BB-Code does not exist in VaultWiki Lite, VaultWiki Lite is unaffected by this issue.

      Details

      The FILE BB-Code vulnerability can allow any user with posting permissions to embed malicious Javascript code on site pages that allow BB-Code. It is relatively easy to exploit, provided the wiki has been setup using a specific configuration that we have historically and will continue to recommend on our web site.

      This vulnerability affects all versions of VaultWiki with the FILE BB-Code active (or a variation of it), including VaultWiki 3.x series, and VaultWiki 2.x series with the Special:Images add-on. Please note that since VaultWiki 3.x received its End-of-Life almost a year ago, there is no patch for that family or earlier, and it is now no longer available for download.

      If you are currently using an unpatched version of VaultWiki, it is highly recommended that you upgrade immediately or disable the FILE BB-Code completely via VaultWiki's Syntax Manager (in 3.x series and earlier, this was called the Wiki Code Manager).

      If you cannot upgrade yet for any number of reasons and disabling the BB-Code is not an option for your site, alternatively you can purchase an Upgrade Service and use it as a request that we manually apply a patch your installed version.

      Please understand that we cannot post specific line-by-line patching instructions without risking being more specific about how to exploit the vulnerability.
      Comments 2 Comments
      1. Alan_SP - October 15, 2014
        • Reply
        I looked and don't have Syntax Manager, or I couldn't find it. I have Wiki Code manager (VW 3.0.20) in ACP, under Vault Wiki optins. But there I don't see FILE BBcode, I have only Special BBcode.

        Do I need to disable Special BBcode with Code manager completely (set all options to No)? Would that be a way to solve this, as I at the moment don't want to upgrade my VW to v4 on my live site.

        Can you make more specific instructions what we should do?
      1. pegasus - October 15, 2014
        • Reply
        For reference, here is the thread regarding disabling FILE under VaultWiki 3.x series: https://www.vaultwiki.org/threads/5700/

      Oops!

       
      Cancel Changes
    • Contact Us
    • License Agreement
    • Privacy
    • Terms
    • Top
    All times are GMT -4. The time now is 3:43 PM.
    This site uses cookies to help personalize content, to tailor your experience, and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Learn more… Accept Remind me later
  • striker
    Powered by vBulletin® Version 4.2.5 Beta 2
    Copyright © 2025 vBulletin Solutions Inc. All rights reserved.
    Search Engine Optimisation provided by DragonByte SEO (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
    Copyright © 2008 - 2024 VaultWiki Team, Cracked Egg Studios, LLC.