Issue List
VWE-2021-6236 is a Permissions escalation issue, where a user can view the title of content they have no permission to view by reading the profile of a user whose last wiki activity involved that content.VWE-2021-6237 is a Permissions escalation issue, where a guest can view the wiki's cached last update even if permissions have changed in the past 5 minutes so that the guest can no longer view that update. The issue affects all versions of the VaultWiki 4.x series.
VWE-2021-6238 is a Permissions escalation issue, where after certain updates to permissions that do not target a specific row by ID, affected users can still view some cached content, even if the update changed their permissions so that they would not be permitted to view that content. The issue affects all versions of the VaultWiki 4.x series.
VWE-2021-6239 is a Permissions escalation issue, where the VaultWiki 3 importer grants custom moderator permissions to the wrong target moderator. The issue affects all versions of the VaultWiki 4.x series, except Lite versions.
VWE-2021-6247 is a Denial of Service issue, where a user can force an existing wiki attachment to become inaccessible by editing it and uploading a new version. The issue affects all versions of the VaultWiki 4.1.x series, on XenForo 2.x platforms only, except Lite versions.
VWE-2021-6249 is a Legal issue, where PNG metadata from XMP profiles are not preserved. Some countries require web sites to preserve XMP metadata. The issue affects VaultWiki 4.0.20 and higher, as well as patches for VWE-2017-4030, except Lite versions.
VWE-2021-6251 is a Denial of Service issue, where a user can force an existing wiki content to become inaccessible by renaming the content, if there is not another content of the same type with an ID matching the renamed content's route ID. The issue affects VaultWiki 4.1.1 Patch Level 2 and higher, except on XenForo 2.x platforms.
VWE-2021-6252 is a Denial of Service amplification issue, where a distributed attack can consume available MySQL connections by submitting extremely high amounts of choices to a bulk chooser's submission script, because the number of choices is not limited prior to querying MySQL. This occurs due to a lack of completeness in the patches for VWE-2016-2034. The issue affects those VaultWiki patches and higher versions.
VWE-2021-6253 is a Denial of Service issue, where a user can leverage fatal errors in the TEMPLATE BB-Code to force any wiki page using certain templates to resolve as a fatal error. The issue affects VaultWiki 4.0.4 and higher, except Lite versions.
VWE-2021-6254 is a Permissions Escalation issue, where a user can view a partial list of a wiki area's feeds by viewing the Recent Feed Updates widget for that area, even though the user does not have permission to view a list of the area's contents. The issue affects VaultWiki 4.0.0 and higher.
VWE-2021-6255 is a Denial of Service issue, where the entire wiki remains disabled after an administrator uses the Rebuild Content URLs tool. The issue affects all versions of the VaultWiki 4.1.x series, on vBulletin-based platforms only.
VWE-2021-6256 is a Permissions Escalation issue, where a user can change the target of a synonym without having permission to edit synonyms. The issue affects all versions of the VaultWiki 4.x series, except Lite versions.
VWE-2021-6257 is a Permissions Escalation issue, where a user can rename a synonym without having permission to rename synonyms. The issue affects all versions of the VaultWiki 4.x series, except Lite versions.
VWE-2021-6258 is a Permissions Escalation issue, where a user can set a synonym's title to a value that appears on the Disallowed Titles list. The issue affects all versions of the VaultWiki 4.x series, except Lite versions.
VWE-2021-6259 is a Denial of Service amplification issue, where a distributed attack by malicious editors can consume all memory allocated to PHP by leveraging massive numbers of template inclusions within complex template fields and saving the affected pages simultaneously. The issue affects VaultWiki 4.1.0 RC 2 and higher, on XenForo 2.x platforms only, except Lite versions.
VWE-2021-6260 is a Permissions Escalation issue, where a custom field that parses BB-Code will render based on the template expansion rules for the maximum wiki page length rather than the maximum field length. The issue affects VaultWiki 4.1.0 RC 2 and higher, on XenForo 2.x platforms only, except Lite versions.
VWE-2021-6261 is a Permissions Escalation issue and occasionally a Data Loss issue, where installer fails to create a new moderator group, forcing administrators to choose an existing usergroup. Choosing an existing group risks permissions escalation and possible locked accounts, because users are added and dropped from the moderator group depending on the user's browsing context. For forums with large numbers of users, this can lead to data loss, because recovering the user's original usergroup assignments would require restoring the database from a backup. The issue affects all versions of the VaultWiki 4.1.x series, except XenForo 2.x platforms.
- Administrators who believe their forum is in this situation should backup their database and reach out for special instructions on changing their moderator group safely, as the patch only restores the ability to create a new usergroup during installation. For new moderators created after version 4.1.3, VaultWiki will additionally attempt to track whether users were already in a usergroup before becoming a moderator to help avoid this problem.
Patches
The following patches address the aforementioned issues:- 4.1.2 Patch Level 3
- 4.1.1 Patch Level 8