Exposure of Private Information ('Privacy Violation') in XWiki platform - CVE-2022-24819
Published: April 8, 2022 / Updated: May 5, 2026
XWiki platform
XWiki
Description
The vulnerability allows a remote attacker to disclose information about wiki users.
The vulnerability exists due to exposure of private personal information to an unauthorized actor in uorgsuggest.vm when handling requests for user-related document suggestions. A remote attacker can request the vulnerable endpoint to disclose information about wiki users.
A guest user without the right to view wiki pages can still list documents related to users of the wiki.