The mail obfuscation configuration was not fully taken into account and is was still possible by obfuscated emails.
See https://jira.xwiki.org/browse/XWIKI-20601 for the reproduction steps.
This has been patched in XWiki 14.10.9, and XWiki 15.3-rc-1.
The workaround is to modify the page XWiki.LiveTableResultsMacros following this patch.
If you have any questions or comments about this advisory:
{
"severity": "MODERATE",
"github_reviewed": true,
"cwe_ids": [
"CWE-402"
],
"nvd_published_at": "2023-11-07T04:17:20Z",
"github_reviewed_at": "2023-07-27T19:28:45Z"
}