The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.
Common Name None VWE-ID VWE-2021-6029 Related Report None Severity MEDIUM Exploit Difficulty EASY Platform XenForo 2.x Description Permissions Escalation. A user can bypass a required custom field by saving a meaningless value, then subsequently editing it to be blank. The subsequent edit will not complain that the required field cannot be left blank. Does not affect Lite versions.
Discovered January 26, 2021 Resolved February 5, 2021 Patches Available 4.1.1 Patch Level 2
4.1.0 Patch Level 4
4.1.0 RC 3 Patch Level 6
4.1.0 RC 2 Patch Level 7
This page has been seen 131,533 times.
-
-
Created by on
-