As of March 8, security patches for March 2024 are now available.
Issue List
VWE-2024-6530 is an Uninstall issue, where uninstallation is interrupted by an E_WARNING if there is a wiki moderator who is neither a super moderator nor a moderator of non-wiki content. The issue affects VaultWiki 4.1.0 Beta 4 and higher, on XenForo 2.x-based platforms only.
VWE-2024-6531 is an Install issue, where a database error prevents access to the install script. The issue affects VaultWiki 4.1.7 and higher, on vBulletin-based platforms only.
VWE-2024-6532 is an Uninstall issue, where a fatal error prevents access to the uninstall script. The issue affects all versions of the VaultWiki 4.1.x series, on XenForo 1.x-based platforms only.
VWE-2024-6534 is an Install issue, where the moderator creation popup does not appear if existing usergroups contain non-UTF-8 characters, preventing the install process from completing. The issue affects all versions of the VaultWiki 4.1.x series, on vBulletin-based platforms only.
VWE-2024-6535 is an Install issue, where a fatal error occurs during installation of default option values. The issue affects VaultWiki 4.1.5 and higher, on XenForo 1.x-based platforms only.
VWE-2024-6537 is a Data Loss issue, where a user who leaves all wiki social groups, or who is a wiki moderator that is removed as wiki moderator, will be removed from all secondary user groups. The issue affects VaultWiki 4.0.9 and higher, on vBulletin-based platforms only.
VWE-2024-6538 is a Permissions Escalation issue, where administrators receive an error when attempting to edit custom permissions for guests within a specific area, preventing them from revoking permissions in that area. The issue affects VaultWiki 4.1.5 and higher, on XenForo-based platforms only.
VWE-2024-6539 is an Install issue, where a fatal error occurs when installing default wiki content, due to a flawed workaround for a bug in XenForo 2.2.13 that leaves parser classes unavailable during installation. The issue affects VaultWiki 4.1.7, on XenForo 2.x-based platforms only.
Patches
The following patches address the aforementioned issues:
Notes
We strongly recommend that all users running VaultWiki in a vBulletin-based production environment update to a patched release. We recommend that all users running VaultWiki in a XenForo-based production environment update to a patched release.