The search functionality in XWiki 0.9.793 indexes cleartext user passwords, which allows remote attackers to obtain sensitive information via a search string that matches a password.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Xwiki | Xwiki | 0.9.793 (including) | 0.9.793 (including) |