Transmission of Private Resources into a New Sphere ('Resource Leak') in XWiki platform - CVE-2023-38509
Published: July 27, 2023 / Updated: May 5, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to transmission of private resources into a new sphere in the live table email sorting functionality when handling sorting of obfuscated email addresses. A remote user can sort by obfuscated email addresses to disclose sensitive information.