Cross-site request forgery in XWiki platform - CVE-2021-32730

 

Cross-site request forgery in XWiki platform - CVE-2021-32730

Published: July 1, 2021 / Updated: May 5, 2026


Vulnerability identifier: #VU130037
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-32730
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify user passwords.

The vulnerability exists due to cross-site request forgery (CSRF) in the password change form when handling password change requests. A remote user can forge a URL to reset the password of any user to modify user passwords.

User interaction is required, and the crafted URL must be accessed by an administrator.


Affected software

XWiki platform

How to mitigate CVE-2021-32730

Install security update from vendor's website.

XWiki platform - addressed in versions 12.10.5, 13.2

External References

Related Security Bulletins