VWE-2019-5280 Printable Version

https://www.vaultwiki.org/pages/Book/Documentation/VWE-2019-5280
This page is a chapter in Info Known Vulnerabilities

This page has been seen 308,157 times.

    • Created by on
      Last updated by on
Common NameNone
VWE-IDVWE-2019-5280
Related ReportNone
SeverityHIGH
Exploit DifficultyEASY
PlatformXenForo 2.1.x
DescriptionSubscription Management. Users may receive push notifications about wiki content, even though they have opted out of those notifications, as long as they are opted in to the corresponding alerts.
DiscoveredJune 25, 2019
ResolvedJuly 14, 2019
Patches Available4.1.0 Beta 2
WorkaroundIn AdminCP > Setup > VaultWiki: Notifications, uncheck Enable Wiki Subscriptions.
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.