Missing Authorization in XWiki platform - CVE-2022-41930
Published: November 21, 2022 / Updated: May 5, 2026
XWiki platform
XWiki
Description
The vulnerability allows a remote attacker to enable or disable user profiles.
The vulnerability exists due to missing authorization in XWiki.XWikiUserProfileSheet when handling requests to change user profile status. A remote attacker can send a crafted request to enable or disable any user profile.
This can allow a disabled user to re-enable themselves.