VWE-2021-6099 Printable Version
This page is a chapter in Info Known Vulnerabilities
This page has been seen 139,066 times.
-
-
Created by on
-
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.
Common Name None VWE-ID VWE-2021-6099 Related Report None Severity HIGH Exploit Difficulty NORMAL Platform Affects all platforms supported by the vulnerable versions. Description Permissions Escalation. A malicious user who can edit the wiki index can change the index into a sub-area, or who can edit index-level feeds can move those feeds to another area, without having permissions to move wiki content. In addition, changing the index to a sub-area can potentially change the way permissions are inherited throughout the wiki for all users, leading to mass additional permissions escalations.
Discovered May 7, 2021 Resolved June 6, 2021 Patches Available 4.1.1 Patch Level 5
4.1.0 Patch Level 7
4.1.0 RC 3 Patch Level 9