The mail obfuscation configuration was not fully taken into account and is was still possible by obfuscated emails.
See https://jira.xwiki.org/browse/XWIKI-20601 for the reproduction steps.
This has been patched in XWiki 14.10.9, and XWiki 15.3-rc-1.
The workaround is to modify the page XWiki.LiveTableResultsMacros following this patch.
If you have any questions or comments about this advisory:
{ "nvd_published_at": "2023-11-07T04:17:20Z", "cwe_ids": [ "CWE-402" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-07-27T19:28:45Z" }