Details
-
Bug
-
Resolution: Fixed
-
Major
-
5.1
-
None
-
Apache 7. Mysql 5.5, XWIKI 5.1
-
Easy
-
N/A
-
N/A
-
Description
There is a CSRF Vulnerability on "Send Message" functionality.
Using this we can send any message,select its visibility and also select whether to send to everyone or any particular user.
Using the parameter "messagestream_message" we can customize the message to send.
Using the parameter "visibilityLevel" we can customize the visibility.
Using the parameter "targetName" we can customize whether to send to a particular user or to all followers.
Vulnerability tested on XWIKI 5.1, so lower versions are also affected.
Attachments
Issue Links
- links to