VWE-2017-4318 Printable Version
This page is a chapter in Info Known Vulnerabilities
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.
Common Name None VWE-ID VWE-2017-4318 Related Report None Severity LOW Exploit Difficulty EASY Platform Affects all platforms supported by the vulnerable versions. Description Permissions Escalation. Possible for users to see cached WIDGET content that they normally don't have permission to view. Does not affect Lite versions.
Discovered December 11, 2017 Resolved January 10, 2018 Patches Available 4.0.20 Patch Level 2
4.0.19 Patch Level 5
4.0.18 Patch Level 6
4.0.17 Patch Level 8
4.0.16 Patch Level 9Workaround In your platform's Custom BB-Code Manager, locate the wiki's WIDGET BB-Code tag, and modify Wiki-Related Options so that the tag is not parsed.