VWE-2010-0136 Printable Version

https://www.vaultwiki.org/pages/Book/Documentation/VWE-2010-0136
This page is a chapter in Info Known Vulnerabilities

This page has been seen 4,757 times.

    • Created by on
Common NameNone
VWE-IDVWE-2010-0136
Related Report#2157
SeverityMEDIUM
Exploit DifficultyNORMAL
PlatformAffects all platforms supported by the vulnerable versions.
DescriptionPermissions escalation. A user can remove attachments from wiki content they do not have permission to edit, as long as the attachment was originally uploaded by them, and as long as they have permission to edit and change attachments for other wiki content.
DiscoveredDecember 13, 2010
ResolvedDecember 17, 2010
Patches Available3.0.8
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.

Notes

After some brief deliberation, this permissions escalation was incorrectly handled as a standard bug at the time it was patched. As a result, patches of other issues for earlier versions in the 3.x series continued to have this issue, even though they were released after this issue was patched.