VWE-2018-4618 Printable Version

https://www.vaultwiki.org/pages/Book/Documentation/VWE-2018-4618
This page is a chapter in Info Known Vulnerabilities

This page has been seen 206,252 times.

    • Created by on
Common NameNone
VWE-IDVWE-2018-4618
Related ReportNone
SeverityLOW
Exploit DifficultyEASY
PlatformAffects all platforms supported by the vulnerable versions.
DescriptionPermissions Escalation. A user can view templated content even though that user has no permission to view the template. Does not affect Lite versions.
DiscoveredJuly 6, 2018
ResolvedJuly 18, 2018
Patches Available4.0.23 Patch Level 1
4.0.22 Patch Level 3
4.0.21 Patch Level 4
4.0.20 Patch Level 7
4.0.19 Patch Level 10
WorkaroundIn the Wiki admin panel, go to Structures > Content Types, and disable the "Template" content-type.
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.