This is an old revision of this page, as edited September 24, 2017, 1:34 PM by pegasus(contribs). It may differ significantly from the current revision.
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.
Common Name None VWE-ID VWE-2017-4075 Related Report None Severity MEDIUM Exploit Difficulty NORMAL Platform Affects all platforms supported by the vulnerable versions. Description Permissions escalation. Using a crafted image file, a user can view thumbnails of any image file hosted on the server. Does not affect VaultWiki Lite.
Discovered September 19, 2017 Resolved September 24, 2017 Patches Available 4.0.19 Patch Level 2
4.0.18 Patch Level 3
4.0.17 Patch Level 5
4.0.16 Patch Level 6
4.0.15 Patch Level 10