• Register
    • Help

    striker  0 Items
    Currently Supporting
    • Home
    • News
      • VaultWiki News
      • Visit the Wiki
    • Forum
    • Wiki
    • Support
    • What's New?
    • Buy Now
    • Manual
    • 
    • Home
    • VaultWiki Moderation Vulnerability & Patches

    1. Welcome to VaultWiki.org, home of the wiki add-on for vBulletin and XenForo!

      VaultWiki allows your existing forum users to collaborate on creating and managing a site's content pages. VaultWiki is a fully-featured and fully-supported wiki solution for vBulletin and XenForo.

      The VaultWiki Team encourages you to join our community of forum administrators and check out VaultWiki for yourself.

    • VaultWiki Moderation Vulnerability & Patches

      by
      pegasus
      • View Profile
      • View Forum Posts
      • View Blog Entries
      • Visit Homepage
      • View Articles
      Published on March 3, 2015 1:57 PM
      6 Comments Comments
      While investigating another unrelated bug report on a client's site over the weekend, our developers discovered that with certain wiki permissions combinations, it was possible for moderated users to publish some changes to existing wiki articles before receiving a moderator's approval.

      Additionally, using a variation of this vulnerability, non-moderated editors might be able to execute otherwise un-permitted changes under XenForo platforms.

      To be clear: this is a security vulnerability, since it compromises the wiki moderation process, circumvents desired permissions, and can result in unwanted content or potentially malicious changes on your wiki.

      To resolve this issue, we have published the following Patch Level releases:
      • 4.0.1 Patch Level 1
      • 4.0.0 Patch Level 1
      • 4.0.0 RC 5 Patch Level 1
      • 4.0.0 RC 4 Patch Level 2
      • 4.0.0 RC 3 Patch Level 3
      • 4.0.0 RC 2 Patch Level 3
      • 4.0.0 RC 1 Patch Level 3


      We highly recommend that all users running VaultWiki 4.x in a production environment upgrade to a patched release as soon as possible.

      This vulnerability affects all supported versions of VaultWiki 4.x, as well as VaultWiki 3.x, but not VaultWiki Lite.

      Details

      This vulnerability can be executed by any user whose wiki edits would be sent to the moderation queue for approval.

      Under XenForo, this vulnerability can be executed by any user who has permission to make edits, whether those edits require approval or not.

      Alternative Mitigation

      The only means of resolving this issue on XenForo platforms is to update to a patched release.

      vBulletin administrators can close this vulnerability without updating to a patched release by removing permission to edit wiki articles from groups and users whose edits are also moderated.

      Since VaultWiki 3.x has already reached its End-of-Life, a patch for that series has not been issued. If you are still running VaultWiki 3.x and you believe the issue details apply to your installation, the only remedies at this time are to update to a patched version or remove permission per the previous paragraph.
      Comments 6 Comments
      1. hollosch - March 5, 2015
        • Reply
        Hi, are there fixed bugs in this version or only the security update ?
      1. pegasus - March 5, 2015
        • Reply
        It's only the security update.
      1. hollosch - March 5, 2015
        • Reply
        Ok, thanks
      1. hollosch - March 5, 2015
        • Reply
        Quote Originally Posted by pegasus View Post
        It's only the security update.
        Do you have a schedule for the next release ?
      1. vhlinks - March 7, 2015
        • Reply
        So if we're running 4.0.1 on vBulletin, do we have to download the entire package again and re-upload everything, or can we just upload the 4.0.1 patch? I ask that because when I download the patch, it looks like they are old files from January of 2015. So I'm a little confused.
      1. pegasus - March 7, 2015
        • Reply
        Patches give you files that were modified in the selected version or newer. In your January 2015 example, it includes files modified from January 2015 (probably not the whole month), February 2015, and March 2015. It will NOT give you files updated from December or before. That's why it's important to only use patches for patching, not upgrading or installing.

      Oops!

       
      Cancel Changes
    • Contact Us
    • License Agreement
    • Privacy
    • Terms
    • Top
    All times are GMT -4. The time now is 2:40 AM.
    This site uses cookies to help personalize content, to tailor your experience, and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Learn more… Accept Remind me later
  • striker
    Powered by vBulletin® Version 4.2.5 Beta 2
    Copyright © 2025 vBulletin Solutions Inc. All rights reserved.
    Search Engine Optimisation provided by DragonByte SEO (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
    Copyright © 2008 - 2024 VaultWiki Team, Cracked Egg Studios, LLC.