VYPR
High severityNVD Advisory· Published May 28, 2021· Updated Aug 3, 2024

Users registered with email verification can self re-activate their disabled accounts

CVE-2021-32620

Description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 11.10.13, 12.6.7, and 12.10.2, a user disabled on a wiki using email verification for registration canouldre-activate themself by using the activation link provided for his registration. The problem has been patched in the following versions of XWiki: 11.10.13, 12.6.7, 12.10.2, 13.0. It is possible to workaround the issue by resetting the validkey property of the disabled XWiki users. This can be done by editing the user profile with object editor.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.xwiki.commons:xwiki-commons-coreMaven
>= 11.6, < 11.10.1311.10.13
org.xwiki.commons:xwiki-commons-coreMaven
>= 12.0, < 12.6.712.6.7
org.xwiki.commons:xwiki-commons-coreMaven
>= 12.10.0, < 12.10.212.10.2

Affected products

2

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.