• Register
    • Help

    striker  0 Items
    Currently Supporting
    • Home
    • News
      • VaultWiki News
      • Visit the Wiki
    • Forum
    • Wiki
    • Support
    • What's New?
    • Buy Now
    • Manual
    • 
    • Home
    • VaultWiki Security Update: March 2019

    1. Welcome to VaultWiki.org, home of the wiki add-on for vBulletin and XenForo!

      VaultWiki allows your existing forum users to collaborate on creating and managing a site's content pages. VaultWiki is a fully-featured and fully-supported wiki solution for vBulletin and XenForo.

      The VaultWiki Team encourages you to join our community of forum administrators and check out VaultWiki for yourself.

    • VaultWiki Security Update: March 2019

      by
      pegasus
      • View Profile
      • View Forum Posts
      • View Blog Entries
      • Visit Homepage
      • View Articles
      Published on March 6, 2019 1:52 PM
      0 Comments Comments
      On February 19, the security patches for March were released early in an effort to rollout fixes for an issue which may have been being used in the wild.

      Issue List

      VWE-2019-5016 is a Permissions Escalation issue, where by guessing the correct editor URL, users are able to post new wiki content without proper permissions. The issue affects new content only; edits to existing content are unaffected.

      Patches

      Important: if you already run one of the following patches but believe you may have downloaded it prior to February 19, 2019, we recommend that you re-download and reapply the patch; there was a problem where our downloader offered some these names for download even though the patch was not released yet or provided patches for different versions than requested.

      As of February 19, 2019, the following patches address the aforementioned issue:
      • 4.1.0 Alpha 2
      • 4.0.25 Patch Level 1
      • 4.0.24 Patch Level 3
      • 4.0.23 Patch Level 5
      • 4.0.22 Patch Level 7
      • 4.0.21 Patch Level 8*

      *A patch was issued for this version even though it reached its end-of-life before the patch date, because the issue was identified prior to its end-of-life. However, we recommend that users update to a more recent patched version.

      We recommend that all users running VaultWiki in a production environment update to a patched release.
    • Contact Us
    • License Agreement
    • Privacy
    • Terms
    • Top
    All times are GMT -4. The time now is 9:08 PM.
    This site uses cookies to help personalize content, to tailor your experience, and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Learn more… Accept Remind me later
  • striker
    Powered by vBulletin® Version 4.2.5 Beta 2
    Copyright © 2025 vBulletin Solutions Inc. All rights reserved.
    Search Engine Optimisation provided by DragonByte SEO (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
    Copyright © 2008 - 2024 VaultWiki Team, Cracked Egg Studios, LLC.