It's possible for forge an URL that, when accessed by an admin, will reset the password of any user in XWiki.
The problem has been patched in XWiki 12.10.5, 13.2RC1.
It's possible to apply the patch manually by modifying the register_macros.vm
template like in https://github.com/xwiki/xwiki-platform/commit/0a36dbcc5421d450366580217a47cc44d32f7257.
https://jira.xwiki.org/browse/XWIKI-18315
If you have any questions or comments about this advisory: * Open an issue in Jira XWiki * Email us at security ML
{ "nvd_published_at": "2021-07-01T18:15:00Z", "github_reviewed_at": "2021-07-02T16:41:31Z", "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-352" ] }