• Register
    • Help

    striker  0 Items
    Currently Supporting
    • Home
    • News
      • VaultWiki News
      • Visit the Wiki
    • Forum
    • Wiki
    • Support
    • What's New?
    • Buy Now
    • Manual
    • 
    • Home
    • VaultWiki Security Update: Cross-Template Vulnerability

    1. Welcome to VaultWiki.org, home of the wiki add-on for vBulletin and XenForo!

      VaultWiki allows your existing forum users to collaborate on creating and managing a site's content pages. VaultWiki is a fully-featured and fully-supported wiki solution for vBulletin and XenForo.

      The VaultWiki Team encourages you to join our community of forum administrators and check out VaultWiki for yourself.

    • VaultWiki Security Update: Cross-Template Vulnerability

      by
      pegasus
      • View Profile
      • View Forum Posts
      • View Blog Entries
      • Visit Homepage
      • View Articles
      Published on October 5, 2015 12:06 PM
      0 Comments Comments
      Over the weekend, while reviewing code for a solution to an unrelated bug report, our developers theorized a security vulnerability in the template feature under XenForo platforms and confirmed it later that day.

      This vulnerability can be exploited by a patient attacker to inject HTML or Javascript into a wiki page via multiple specially-crafted templates with a success rate of approximately 1 in 50,000 uncached views of that wiki page. Of course, a long-lived page cache lowers the success rate with respect to total views and can approach 0% over short periods over time. However, once the attack is successful the wiki page can also be cached in the succeeded state and thereafter have a success rate of 100%.

      This issue affects VaultWiki versions 4.0.0 Gamma 1 - 4.0.6, but does not affect VaultWiki Lite. This issue affects XenForo-based installations only.

      We have published the following Patch Level releases to resolve this issue:
      • 4.0.6 Patch Level 1
      • 4.0.5 Patch Level 1
      • 4.0.4 Patch Level 1
      • 4.0.3 Patch Level 2
      • 4.0.2 Patch Level 5
      • 4.0.1 Patch Level 8
      • 4.0.0 Patch Level 7
      • 4.0.0 RC 5 Patch Level 6
      • 4.0.0 RC 4 Patch Level 7


      We highly recommend that all users running VaultWiki 4.x under XenForo in a production environment upgrade to a patched release as soon as possible.
    • Contact Us
    • License Agreement
    • Privacy
    • Terms
    • Top
    All times are GMT -4. The time now is 4:55 PM.
    This site uses cookies to help personalize content, to tailor your experience, and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Learn more… Accept Remind me later
  • striker
    Powered by vBulletin® Version 4.2.5 Beta 2
    Copyright © 2025 vBulletin Solutions Inc. All rights reserved.
    Search Engine Optimisation provided by DragonByte SEO (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
    Copyright © 2008 - 2024 VaultWiki Team, Cracked Egg Studios, LLC.