• Register
    • Help

    striker  0 Items
    Currently Supporting
    • Home
    • News
      • VaultWiki News
      • Visit the Wiki
    • Forum
    • Wiki
    • Support
    • What's New?
    • Buy Now
    • Manual
    • 
    • Home
    • VaultWiki News

    1. Welcome to VaultWiki.org, home of the wiki add-on for vBulletin and XenForo!

      VaultWiki allows your existing forum users to collaborate on creating and managing a site's content pages. VaultWiki is a fully-featured and fully-supported wiki solution for vBulletin and XenForo.

      The VaultWiki Team encourages you to join our community of forum administrators and check out VaultWiki for yourself.

    • VaultWiki News RSS Feed

      VaultWiki Security Update: July 2021 

      by
      pegasus
      • View Profile
      • View Forum Posts
      • View Blog Entries
      • Visit Homepage
      • View Articles
      Published on July 25, 2021 3:00 AM

      As of July 25, security patches for July 2021 are now available.

      Issue List

      VWE-2021-6131 is a Subscription Management issue, where the wrong user may receive a notification when a moderator takes action against a user's wiki content. The issue affects all versions of the VaultWiki 4.x series.

      VWE-2021-6136 is a Data Loss issue, where when renaming content, a user can unintentionally change all synonyms attached to that content into double redirects. The issue affects VaultWiki 4.0.16 and higher.

      VWE-2021-6139 is a Permissions Escalation issue, where when renaming content, the rename is completed without a valid synonym, even if the user does not have permission to rename without generating a synonym. The issue affects VaultWiki 4.0.16 and higher.

      VWE-2021-6145 is a Permissions Escalation issue, by which a user who can move content to another area can also send it to the approval queue, even though the user does not have permission to moderate content. The issue affects VaultWiki 4.1.0 RC 2 and higher.

      VWE-2021-6148 is a Data Loss issue, where deferred tasks containing a reference to triggering content can fail to queue due to custom field assignments or unencoded IP data, resulting in data denormalization, orphaned content, and other effects. The issue affects VaultWiki 4.1.0 RC 2 and higher.

      Patches

      The following patches address the aforementioned issues:
      • 4.1.2 Patch Level 1
      • 4.1.1 Patch Level 6
      • 4.1.0 Patch Level 8


      Notes

      We strongly recommend that all users running VaultWiki in a production environment update to a patched release.

      VaultWiki Security Update: June 2021 

      by
      pegasus
      • View Profile
      • View Forum Posts
      • View Blog Entries
      • Visit Homepage
      • View Articles
      Published on June 6, 2021 1:33 PM

      As of June 6, security patches for June 2021 are now available.

      Issue List

      VWE-2021-6097 is a MySQL Injection issue, where users may be able to perform arbitrary MySQL by utilizing a flaw in platform-based attachment management. The issue affects all versions of the VaultWiki 4.x series.

      VWE-2021-6098 is a Permissions Escalation issue, where a user can associate platform-based attachments to wiki comments, even though those attachments were uploaded by another user account with different attachment permissions and/or quotas, or by the same user account under a different context with different attachment permissions and/or quotas. The issue affects all versions of the VaultWiki 4.x series.*

      * Please be aware that variations of the same issue also affect basic content-types on stock installations of both vBulletin and XenForo. XenForo developers have been notified of the issue, but as of this notice, the issue has not yet been addressed. Since vBulletin 4.x and lower is already end-of-life, this would never be patched by vBulletin's developers. In the absence of a patch, the only way to prevent this issue from being exploited would be to disable all platform-based attachments (posts, conversations, etc) that are not patched. Also, depending on the method, a future XenForo patch could break the fix that we have applied to wiki comments.

      VWE-2021-6099 is a Permissions Escalation issue, where a malicious user who can edit the wiki index can also change the index into a sub-area, or who can edit index-level feeds can move those feeds to another area. The issue affects VaultWiki 4.1.0 Alpha 1 and higher.

      VWE-2021-6100 is an HTML Injection issue, where when previewing content or displaying an error, an editor field is presented again after submission without reencoding the submitted value. The issue affects all versions of the VaultWiki 4.x series.

      VWE-2021-6101 is an HTML Injection issue, where when previewing content or displaying an error, an editor field is presented again after submission without reencoding the submitted value. The issue affects all versions of the VaultWiki 4.x series, but only on vBulletin-based platforms.

      VWE-2021-6102 is an HTML Injection issue, where usernames are not displayed consistently in an escaped format. The issue affects all versions of the VaultWiki 4.x series, but only on XenForo-based platforms.

      VWE-2021-6103 is an HTML Injection issue, where certain IP address values are not displayed in an escaped format. The issue affects the VaultWiki 2.2.x-2.5.x series, the VaultWiki 3.x series, and the VaultWiki 4.x series.

      VWE-2021-6104 is an HTML Injection issue, where certain fields are not escaped properly in the wiki's RSS feeds. The issue affects all versions of the VaultWiki 4.x series.

      VWE-2021-6105 is a Permissions Escalation issue, where a user can associate wiki-based files to wiki attachments, even though those files were uploaded under a different context with different attachment permissions, or even though those files are associated to an existing attachment that was created by another user or context with different attachment permissions. The issue affects all versions of the VaultWiki 2.x, 3.x, and 4.x series.

      VWE-2021-6106 is a Permissions Escalation issue, where a user can upload wiki-based files even though those files are not permitted in the selected target area. The issue affects all versions of the VaultWiki 4.x series.

      VWE-2021-6107 is a Permissions Escalation issue, where it is possible to upload an image with dimensions larger than the maximum permitted dimensions via a specially-crafted image file that exceeds the maximum permitted file size. The issue affects all versions of the VaultWiki 4.x series.

      Patches

      The following patches address the aforementioned issues:
      • 4.1.1 Patch Level 5
      • 4.1.0 Patch Level 7
      • 4.1.0 RC 3 Patch Level 9*

      *A patch was issued for this version even though it reached its end-of-life before the patch date, because at least one of the addressed issues was identified prior to its end-of-life. However, we recommend that users update to a more recent patched version.

      Notes

      We strongly recommend that all users running VaultWiki in a production environment update to a patched release.

      VaultWiki Security Update: May 2021 

      by
      pegasus
      • View Profile
      • View Forum Posts
      • View Blog Entries
      • Visit Homepage
      • View Articles
      Published on May 3, 2021 1:00 PM

      As of May 3, security patches for May 2021 are now available.

      Issue List

      VWE-2021-6051 is a MySQL Injection issue, where a malicious administrator can execute arbitrary MySQL statements by utilizing a flaw in integration position management. The issue affects VaultWiki 4.1.0 Alpha 1 and higher.

      VWE-2021-6076 is an HTML Injection issue, where a malicious editor can save specially crafted content that is later loaded as WYSIWYG editor content by an unsuspecting user editing the same page, and if the second user opens certain editor dialogs while having that content selected, the content can be displayed to the user unescaped. The issue affects all versions of the VaultWiki 4.x series.

      VWE-2021-6087 is a Denial of Service issue, where a malicious editor can leverage fatal errors in handling of the WIDGET BB-Code's "sidebar" variant in order to cause any page they edit to resolve as a fatal error. The issue affects VaultWiki 4.1.0 Alpha 1 and higher, but only on XenForo 2.x platforms.

      Patches

      The following patches address the aforementioned issues:
      • 4.1.1 Patch Level 4
      • 4.1.0 Patch Level 6
      • 4.1.0 RC 3 Patch Level 8


      Notes

      We strongly recommend that all users running VaultWiki in a production environment update to a patched release.

      VaultWiki Security Update: March 2021 

      by
      pegasus
      • View Profile
      • View Forum Posts
      • View Blog Entries
      • Visit Homepage
      • View Articles
      Published on March 5, 2021 5:44 PM

      As of March 5, security patches for March 2021 are now available.

      Issue List

      VWE-2021-6177 is a Permissions Escalation issue, under which, when the last editor and original creator of a wiki page are different, the last editor of the page can protect the page so that only the creator can make changes, without the original creator's knowledge or consent. In such a case, until the original creator submits a new edit, even the original creator has no access to the controls necessary to reverse the protection. The issue affects VaultWiki 4.0.20 and higher.

      Patches

      The following patches address the aforementioned issue:
      • 4.1.1 Patch Level 3
      • 4.1.0 Patch Level 5
      • 4.1.0 RC 3 Patch Level 7
      • 4.1.0 RC 2 Patch Level 8


      Notes

      We recommend that all users running VaultWiki in a production environment update to a patched release.

      VaultWiki Security Update: February 2021 

      by
      pegasus
      • View Profile
      • View Forum Posts
      • View Blog Entries
      • Visit Homepage
      • View Articles
      Published on February 5, 2021 7:50 PM

      As of February 5, security patches for February 2021 are now available.

      Issue List

      VWE-2021-6029 is a Permissions Escalation issue, by which users can bypass a required custom field by saving a meaningless value, then subsequently editing it to be blank; the subsequent edit does not complain that the required field was left blank. The issue affects VaultWiki 4.1.0 RC 2 and higher.

      VWE-2021-6038 is a Permissions Escalation issue, where an improperly incrementing database key can cause some users to see wiki navigation links based on the permissions of another user. The issue affects VaultWiki 4.0.24 and higher.

      Patches

      The following patches address the aforementioned issues:
      • 4.1.1 Patch Level 2
      • 4.1.0 Patch Level 4
      • 4.1.0 RC 3 Patch Level 6
      • 4.1.0 RC 2 Patch Level 7


      4.0.x Retires

      This week marked the 1-year anniversary of VaultWiki 4.0.28, which was the last release in the 4.0.x series. Being more than 1 year old, it is no longer eligible for security updates. Because today's security update includes issues affecting 4.0.28, it is no longer considered safe to use and has been removed from the download menu. Consequently, there is now no public access to any 4.0.x version. If you were still waiting to upgrade to 4.1.x, that time is now.

      Notes

      We recommend that all users running VaultWiki in a production environment update to a patched release.

      VaultWiki Security Update: December 2020 

      by
      pegasus
      • View Profile
      • View Forum Posts
      • View Blog Entries
      • Visit Homepage
      • View Articles
      Published on December 13, 2020 3:37 PM

      As of December 13, security patches for December 2020 are now available.

      Issue List

      VWE-2020-6005 is a Permissions Escalation issue, where records of used links, wanted categories, and template usages become updated by edits that still required moderator approval. The issue affects VaultWiki 2.0.0 Beta 3 and higher, including all prior versions of the VaultWiki 3.x and 4.x series.

      VWE-2020-6013 is a Permissions Escalation issue, whereby accessing the correct URL directly, a user without permission to manage a feed's entries can access the form that allows modifying an individual entry; however, the user would not be able to save any attempted changes. The issue affects VaultWiki 4.0.0 and higher.

      VWE-2020-6019 is a Permissions Escalation issue, where users who were granted permission to disambiguate content prior to the patch for VWE-2020-5862 are forever able to perform many other unrelated tasks regardless of their other permissions. The issue affects VaultWiki 4.1.0 RC 3 and higher.

      Patches

      The following patches address the aforementioned issues:
      • 4.1.1 Patch Level 1
      • 4.1.0 Patch Level 3
      • 4.1.0 RC 3 Patch Level 5
      • 4.1.0 RC 2 Patch Level 6
      • 4.1.0 RC 1 Patch Level 7
      • 4.0.28 Patch Level 7


      Notes

      We recommend that all users running VaultWiki in a production environment update to a patched release.

      VaultWiki 4.1.1 

      by
      pegasus
      • View Profile
      • View Forum Posts
      • View Blog Entries
      • Visit Homepage
      • View Articles
      Published on December 13, 2020 3:14 PM

      Last month VaultWiki 4.1.1 became available for licensed customers. This version is a maintenance release with over 50 bug fixes and style tweaks.

      For a list of changes in this release, please see Changelog for 4.1.1. If you are a style or language pack maintainer, please check here for changes which may affect you.

      Page 3 of 31 FirstFirst Previous 1234513 ... Next LastLast
    • Contact Us
    • License Agreement
    • Privacy
    • Terms
    • Top
    All times are GMT -4. The time now is 4:05 PM.
    This site uses cookies to help personalize content, to tailor your experience, and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Learn more… Accept Remind me later
  • striker
    Powered by vBulletin® Version 4.2.5 Beta 2
    Copyright © 2023 vBulletin Solutions Inc. All rights reserved.
    Search Engine Optimisation provided by DragonByte SEO (Pro) - vBulletin Mods & Addons Copyright © 2023 DragonByte Technologies Ltd.
    Copyright © 2008 - 2013 VaultWiki Team, Cracked Egg Studios, LLC.