VWE-2017-4318 Printable Version

https://www.vaultwiki.org/pages/Book/Documentation/VWE-2017-4318
This page is a chapter in Info Known Vulnerabilities

This page has been seen 366,629 times.

    • Created by on
      Last updated by on
Common NameNone
VWE-IDVWE-2017-4318
Related ReportNone
SeverityLOW
Exploit DifficultyEASY
PlatformAffects all platforms supported by the vulnerable versions.
DescriptionPermissions Escalation. Possible for users to see cached WIDGET content that they normally don't have permission to view. Does not affect Lite versions.
DiscoveredDecember 11, 2017
ResolvedJanuary 10, 2018
Patches Available4.0.20 Patch Level 2
4.0.19 Patch Level 5
4.0.18 Patch Level 6
4.0.17 Patch Level 8
4.0.16 Patch Level 9
WorkaroundIn your platform's Custom BB-Code Manager, locate the wiki's WIDGET BB-Code tag, and modify Wiki-Related Options so that the tag is not parsed.
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.