VWE-2017-3733 Printable Version

https://www.vaultwiki.org/pages/Book/Documentation/VWE-2017-3733
This page is a chapter in Info Known Vulnerabilities

This page has been seen 310,461 times.

    • Created by on
      Last updated by on
Common NameNone
VWE-IDVWE-2017-3733
Related ReportNone
SeverityMEDIUM
Exploit DifficultyEASY
PlatformAffects all platforms supported by the vulnerable versions.
DescriptionPermissions escalation in wiki attachments. With collusion of downloading users, uploading users can circumvent some attachment-related permissions. Does not affect Lite versions.
DiscoveredApril 16, 2017
ResolvedMay 16, 2017
Patches Available4.0.17 Patch Level 2
4.0.16 Patch Level 3
4.0.15 Patch Level 7
4.0.14 Patch Level 10
4.0.13 Patch Level 10
4.0.12 Patch Level 11
4.0.11 Patch Level 11
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.

Notes

Attachments that were already violation of the rules prior to applying the patch must be identified and moderated manually.