XWiki AdminTools
cpe:2.3:a:xwiki:admin_tools:*:*:*:*:*:*:*
- <= 1.0.1
A vulnerability in XWiki AdminTools versions through 1.0.1 allows users without admin rights to access the AdminTools.SpammedPages feature. Although no data is displayed to non-admin users, the page remains accessible. This issue has been resolved in version 1.1. As a workaround, the view rights for the AdminTools space can be restricted to the XWikiAdminGroup.
This vulnerability could lead to unauthorized access to the AdminTools.SpammedPages feature by non-admin users.
Users can upgrade to XWiki AdminTools version 1.1 or set the view rights for the AdminTools space to be available only for the XWikiAdminGroup.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.