GHSA-76mp-659p-rw65

    Dashboard / Vulnerabilities / GHSA-76mp-659p-rw65

    GHSA-76mp-659p-rw65

    Published: 18 May 2021Last Modified: 8 Jul 2026

    Summary: XWiki users registered with email verification can self re-activate their disabled accounts

    Details: ### Impact A user disabled on a wiki using email verification for registration can re-activate himself by using the activation link provided for his registration. ### Patches The problem has been patched in the following versions of XWiki: 11.10.13, 12.6.7, 12.10.2, 13.0. ### Workarounds It's possible to workaround the issue by resetting the `validkey` property of the disabled XWiki users. This can be done by editing the user profile with object editor. ### References https://jira.xwiki.org/browse/XWIKI-17942 ### For more information If you have any questions or comments about this advisory: * Open an issue in [Jira](http://jira.xwiki.org) * Email us at [Security mailing-list](mailto:[email protected])

    Affected packages

    Package

    Name: org.xwiki.commons:xwiki-commons-core

    Purl: pkg:maven/org.xwiki.commons/xwiki-commons-core

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 11.6
    Fixed -11.10.13

    Affected versions

    11.10
    11.10.1
    11.10.10
    11.10.11
    11.10.12
    11.10.2
    11.10.3
    11.10.4
    11.10.5
    11.10.6
    11.10.7
    11.10.8

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-76mp-659p-rw65 | CVE-DB