Impact
It's possible for forge an URL that, when accessed by an admin, will reset the password of any user in XWiki.
Patches
The problem has been patched in XWiki 12.10.5, 13.2RC1.
Workarounds
It's possible to apply the patch manually by modifying the register_macros.vm
template like in 0a36dbc.
References
https://jira.xwiki.org/browse/XWIKI-18315
For more information
If you have any questions or comments about this advisory:
Impact
It's possible for forge an URL that, when accessed by an admin, will reset the password of any user in XWiki.
Patches
The problem has been patched in XWiki 12.10.5, 13.2RC1.
Workarounds
It's possible to apply the patch manually by modifying the
register_macros.vm
template like in 0a36dbc.References
https://jira.xwiki.org/browse/XWIKI-18315
For more information
If you have any questions or comments about this advisory: