Details
-
Bug
-
Resolution: Incomplete
-
Major
-
None
-
6.1-rc-1
-
None
-
All environments
-
Hard
-
Description
XWiki has a vulnerability which allows any registered user to reset the admin password and so become admin.
By inserting a modified velocity script, it is possible to generate a password reset link that works and gets processed on the server side. This is only possible for the author of a certain wiki page. However if you edit a page created by an administrator, in the example I attached the standard first blog post page, it is possible to execute the velocity script with admin rights and so to reset the admin password. I will also include the modified velocityscript.