Information disclosure in XWiki platform - CVE-2022-23619

 

Information disclosure in XWiki platform - CVE-2022-23619

Published: February 9, 2022 / Updated: May 5, 2026


Vulnerability identifier: #VU130031
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-23619
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to exposure of sensitive information in the "Forgot your password?" form when handling password reset requests. A remote attacker can submit a username to determine whether an account exists to disclose sensitive information.

The issue can be exploited even if the wiki is closed to guest users.


Affected software

XWiki platform

How to mitigate CVE-2022-23619

Install security update from vendor's website.

XWiki platform - addressed in versions 12.10.9, 13.4.1, 13.6

External References

Related Security Bulletins