VWE-2019-5266 Printable Version

https://www.vaultwiki.org/pages/Book/Documentation/VWE-2019-5266
This page is a chapter in Info Known Vulnerabilities

This page has been seen 188,081 times.

    • Created by on
Common NameNone
VWE-IDVWE-2019-5266
Related Report#5779
SeverityMEDIUM
Exploit DifficultyNORMAL
PlatformXenForo 2.x
DescriptionPermissions Escalation. Users can use specially crafted BB-Codes and template parameters to circumvent area parser settings. Does not affect Lite versions.
DiscoveredMay 31, 2019
ResolvedJune 7, 2019
Patches Available4.1.0 Beta 2
WorkaroundIn AdminCP > Wiki > Structures > Content Types, disable the Template type.
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.