• Register
    • Help

    striker  0 Items
    Currently Supporting
    • Home
    • News
      • VaultWiki News
      • Visit the Wiki
    • Forum
    • Wiki
    • Support
    • What's New?
    • Buy Now
    • Manual
    • 
    • Home
    • VaultWiki Security Update: May 2022

    1. Welcome to VaultWiki.org, home of the wiki add-on for vBulletin and XenForo!

      VaultWiki allows your existing forum users to collaborate on creating and managing a site's content pages. VaultWiki is a fully-featured and fully-supported wiki solution for vBulletin and XenForo.

      The VaultWiki Team encourages you to join our community of forum administrators and check out VaultWiki for yourself.

    • VaultWiki Security Update: May 2022

      by
      pegasus
      • View Profile
      • View Forum Posts
      • View Blog Entries
      • Visit Homepage
      • View Articles
      Published on May 3, 2022 2:27 PM
      0 Comments Comments
      As of May 3, security patches for May 2022 are now available.

      Issue List

      VWE-2022-6416 is an Information Disclosure issue, where some variants of the VAR BB-Code allow any wiki editor to view and publicize the current VaultWiki version number. The issue affects VaultWiki 4.0.19 and higher. Prior to 4.0.19, Information Disclosures were not treated as security issues.

      VWE-2022-6420 is an HTML Injection issue, where by leveraging a flaw in the cropping of overly-long WIKI BB-Code usages, a malicious user can modify the expected contents of HTML blocks outside the intended user-generated content locations. The issue affects VaultWiki 4.0.9 and higher, as well as earlier patches for VWE-2016-2072.

      VWE-202206426 is a Denial of Service issue, where on some hosts and server configurations, VaultWiki's deferred tasks trigger a false-positive in denial-of-service protective measures, which causes some visitors to inappropriately receive temporary bans or for the hosting account to be temporarily suspended, because the web-based deferred tasks may be processed in rapid succession. The issue affects all versions of the VaultWiki 4.x series, although the issue is more pronounced on XenForo-based platforms.

      Patches

      The following patches address the aforementioned issues:
      • 4.1.4 Patch Level 2
      • 4.1.3 Patch Level 4
      • 4.1.2 Patch Level 6


      Notes

      We highly recommend that all users running VaultWiki in a production environment update to a patched release as soon as they are able.
    • Contact Us
    • License Agreement
    • Privacy
    • Terms
    • Top
    All times are GMT -4. The time now is 4:44 AM.
    This site uses cookies to help personalize content, to tailor your experience, and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Learn more… Accept Remind me later
  • striker
    Powered by vBulletin® Version 4.2.5 Beta 2
    Copyright © 2023 vBulletin Solutions Inc. All rights reserved.
    Search Engine Optimisation provided by DragonByte SEO (Pro) - vBulletin Mods & Addons Copyright © 2023 DragonByte Technologies Ltd.
    Copyright © 2008 - 2013 VaultWiki Team, Cracked Egg Studios, LLC.