• Register
    • Help

    striker  0 Items
    Currently Supporting
    • Home
    • News
      • VaultWiki News
      • Visit the Wiki
    • Forum
    • Wiki
    • Support
    • What's New?
    • Buy Now
    • Manual
    • 
    • Home
    • VaultWiki Security Update: November 2019

    1. Welcome to VaultWiki.org, home of the wiki add-on for vBulletin and XenForo!

      VaultWiki allows your existing forum users to collaborate on creating and managing a site's content pages. VaultWiki is a fully-featured and fully-supported wiki solution for vBulletin and XenForo.

      The VaultWiki Team encourages you to join our community of forum administrators and check out VaultWiki for yourself.

    • VaultWiki Security Update: November 2019

      by
      pegasus
      • View Profile
      • View Forum Posts
      • View Blog Entries
      • Visit Homepage
      • View Articles
      Published on November 15, 2019 9:23 AM
      0 Comments Comments
      As of November 15, the security patches for November 2019 are now available.

      Issue List

      VWE-2019-5425 is a Permissions escalation, where users can view the output of embedded templates that were soft-deleted or rejected, even if they don't have staff permissions, as long as the page where the template was embedded was cached when viewed by another user who had the appropriate permission. The issue affects all versions of the VaultWiki 4.x series.

      Patches

      The following patches address the aforementioned issues:
      • 4.0.27 Patch Level 2
      • 4.0.26 Patch Level 4
      • 4.0.25 Patch Level 6


      4.1.x Issues

      Since beta versions are not subject to the same patching policy as stable versions, the issue listed above is patched in a new build in the 4.1.x branch, 4.1.0 Beta 4 build 005. In addition, the following issue is known to have affected a prior build. To stay protected, please make sure you are running the latest build of the beta.

      VWE-2019-5416 is a Permissions escalation, where wiki page contents are rendered using the viewing user's parser-related permissions for wiki comments that they post, rather than the appropriate parser-related area settings for wiki pages. The issue affects early downloads of 4.1.0 Beta 4 build 001 only, and only on vBulletin 4.x platforms. Users already running a later build or using VaultWiki on a different platform are not affected by this issue.

      Notes

      We recommend that all users running VaultWiki in a production environment update to a patched release as soon as they are able.
    • Contact Us
    • License Agreement
    • Privacy
    • Terms
    • Top
    All times are GMT -4. The time now is 9:16 PM.
    This site uses cookies to help personalize content, to tailor your experience, and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Learn more… Accept Remind me later
  • striker
    Powered by vBulletin® Version 4.2.5 Beta 2
    Copyright © 2025 vBulletin Solutions Inc. All rights reserved.
    Search Engine Optimisation provided by DragonByte SEO (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
    Copyright © 2008 - 2024 VaultWiki Team, Cracked Egg Studios, LLC.