VWE-2021-6029 Printable Version

https://www.vaultwiki.org/pages/Book/Documentation/VWE-2021-6029
This page is a chapter in Info Known Vulnerabilities

This page has been seen 74,468 times.

    • Created by on
Common NameNone
VWE-IDVWE-2021-6029
Related ReportNone
SeverityMEDIUM
Exploit DifficultyEASY
PlatformXenForo 2.x
DescriptionPermissions Escalation. A user can bypass a required custom field by saving a meaningless value, then subsequently editing it to be blank. The subsequent edit will not complain that the required field cannot be left blank. Does not affect Lite versions.
DiscoveredJanuary 26, 2021
ResolvedFebruary 5, 2021
Patches Available4.1.1 Patch Level 2
4.1.0 Patch Level 4
4.1.0 RC 3 Patch Level 6
4.1.0 RC 2 Patch Level 7
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.