VWE-2016-3120 Printable Version

https://www.vaultwiki.org/pages/Book/Documentation/VWE-2016-3120
This page is a chapter in Info Known Vulnerabilities

This page has been seen 178,187 times.

    • Created by on
      Last updated by on
Common NameRestricted Area Vulnerability
VWE-IDVWE-2016-3120
Related ReportNone
SeverityMEDIUM
Exploit DifficultyEASY
PlatformAffects all platforms supported by the vulnerable versions.
DescriptionPermissions escalation. Permissions are not revoked correctly. Does not affect Lite versions.
DiscoveredDecember 22, 2016
ResolvedDecember 22, 2016
Patches Available4.0.15 Patch Level 3
4.0.14 Patch Level 6
4.0.13 Patch Level 6
4.0.12 Patch Level 7
4.0.11 Patch Level 7
4.0.10 Patch Level 8
4.0.9 Patch Level 8
4.0.8 Patch Level 10
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.

Additional Instructions

After applying one of these patches:
  1. Go to the Wiki Admin Panel > Permissions > Usergroups.
  2. Edit the Administrators group.
  3. Change "Index Permissions" > "Can view the wiki Index?" to a different value.
  4. Save.
  5. Edit the Administrators group again.
  6. Change "Index Permissions" > "Can view the wiki Index?" back to the previous value.
  7. Save.
This will remove cached permissions that might have been stored in a vulnerable state from your site's cache.