• Register
    • Help

    striker  0 Items
    Currently Supporting
    • Home
    • News
      • VaultWiki News
      • Visit the Wiki
    • Forum
    • Wiki
    • Support
    • What's New?
    • Buy Now
    • Manual
    • 
    • Home
    • VaultWiki Security Update: April 2020

    1. Welcome to VaultWiki.org, home of the wiki add-on for vBulletin and XenForo!

      VaultWiki allows your existing forum users to collaborate on creating and managing a site's content pages. VaultWiki is a fully-featured and fully-supported wiki solution for vBulletin and XenForo.

      The VaultWiki Team encourages you to join our community of forum administrators and check out VaultWiki for yourself.

    • VaultWiki Security Update: April 2020

      by
      pegasus
      • View Profile
      • View Forum Posts
      • View Blog Entries
      • Visit Homepage
      • View Articles
      Published on April 7, 2020 1:57 PM
      0 Comments Comments
      As of April 7, security patches for April 2020 are now available.

      Issue List

      VWE-2020-5643 is a Subscription Management issue, where alerts for likes or reactions of content the user contributed to are sent even if that user is not opted-in to that alert. The issue affects XenForo 2.x-based platforms only.

      VWE-2020-5645 is a Local File Inclusion issue, whereby a malicious attacker can load VaultWiki PHP files into memory outside of the intended execution pattern for those files. However, the attacker receives a fatal error when doing so. The issue affects all versions of VaultWiki 4.x series.

      VWE-2020-5727 is an HTML Injection issue, where unescaped HTML can appear in keywords, description, and other META elements. The issue affects all versions of VaultWiki 4.x series.

      VWE-2020-5774 is a Permissions Escalation issue, by which users can leverage assignment form filters to retrieve a list of containers they don't have permission to view, as long as they have permission to view the container's area's content list. The issue affects all versions of VaultWiki 4.x series.

      Patches

      The following patches address the aforementioned issues:
      • 4.1.0 RC 2 Patch Level 1
      • 4.1.0 RC 1 Patch Level 2
      • 4.0.28 Patch Level 2
      • 4.0.27 Patch Level 5
      • 4.0.26 Patch Level 7


      Notes

      We highly recommend that all users running VaultWiki in a production environment update to a patched release.
    • Contact Us
    • License Agreement
    • Privacy
    • Terms
    • Top
    All times are GMT -4. The time now is 9:18 PM.
    This site uses cookies to help personalize content, to tailor your experience, and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Learn more… Accept Remind me later
  • striker
    Powered by vBulletin® Version 4.2.5 Beta 2
    Copyright © 2025 vBulletin Solutions Inc. All rights reserved.
    Search Engine Optimisation provided by DragonByte SEO (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
    Copyright © 2008 - 2024 VaultWiki Team, Cracked Egg Studios, LLC.