• Register
    • Help

    striker  0 Items
    Currently Supporting
    • Home
    • News
      • VaultWiki News
      • Visit the Wiki
    • Forum
    • Wiki
    • Support
    • What's New?
    • Buy Now
    • Manual
    • 
    • Home
    • VaultWiki Security Update: January 2022

    1. Welcome to VaultWiki.org, home of the wiki add-on for vBulletin and XenForo!

      VaultWiki allows your existing forum users to collaborate on creating and managing a site's content pages. VaultWiki is a fully-featured and fully-supported wiki solution for vBulletin and XenForo.

      The VaultWiki Team encourages you to join our community of forum administrators and check out VaultWiki for yourself.

    • VaultWiki Security Update: January 2022

      by
      pegasus
      • View Profile
      • View Forum Posts
      • View Blog Entries
      • Visit Homepage
      • View Articles
      Published on January 1, 2022 1:43 PM
      0 Comments Comments
      As of January 1, security patches for January 2022 are now available.

      Issue List

      VWE-2021-6355 is a Phishing issue, where user-positioned elements are not restricted within the relevant position's container when viewing previous page revisions. The issue affects VaultWiki 4.0.18 and higher, as well as patches for VWE-2017-3734.

      VWE-2021-6363 is a Permissions Escalation issue, where a user can use a specially-crafted form submission to save more than the maximum allowed number of attachments per wiki comment. The issue affects all versions of the VaultWiki 4.x series.*

      VWE-2021-6358 is a Denial of Service issue, where the entire wiki remains disabled after an administrator performs changes that trigger certain rebuild tasks. The issue affects VaultWiki 4.1.3 and higher.

      VWE-2021-6359 is a Denial of Service issue, where the entire wiki remains disabled after an administrator changes the option Force URLs to Lower-Case. The issue affects all prior versions of the VaultWiki 4.1.x series.

      VWE-2021-6364 is a Permissions Escalation issue, where a user can associate an attachment to comments even though permission to add attachments has been revoked since the user uploaded the attachment.*

      * Please be aware that variations of these same issues also affect basic content-types on stock installations of both vBulletin and XenForo.

      Additionally, some improvements have been made regarding changes from some prior 2021 patches, where certain functionality had been adversely affected by the earlier patch.

      Patches

      The following patches address the aforementioned issues:
      • 4.1.3 Patch Level 2
      • 4.1.2 Patch Level 5


      Notes

      We recommend that all users running VaultWiki in a production environment update to a patched release.
    • Contact Us
    • License Agreement
    • Privacy
    • Terms
    • Top
    All times are GMT -4. The time now is 6:37 AM.
    This site uses cookies to help personalize content, to tailor your experience, and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Learn more… Accept Remind me later
  • striker
    Powered by vBulletin® Version 4.2.5 Beta 2
    Copyright © 2025 vBulletin Solutions Inc. All rights reserved.
    Search Engine Optimisation provided by DragonByte SEO (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
    Copyright © 2008 - 2024 VaultWiki Team, Cracked Egg Studios, LLC.