XWiki up to 13.1 Reset Password information disclosure

A vulnerability was found in XWiki up to 13.1 (Content Management System). It has been declared as problematic. Affected by this vulnerability is an unknown part of the component Reset Password Handler. Upgrading to version 13.2RC1 eliminates this vulnerability. Applying a patch is able to eliminate this problem. The bugfix is ready for download at github.com. The best possible mitigation is suggested to be upgrading to the latest version.

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2024-4267 : PARISNEO LOLLMS-WEBUI UP TO 9.5 OPEN_FILE COMMAND INJECTION

CVE-2024-4267 : PARISNEO LOLLMS-WEBUI UP TO 9.5 OPEN_FILE COMMAND INJECTION

Description A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically within the ‘open_file’ module, version 9.5. The vulnerability

CVE-2024-29849 : VEERAM BACKUP & REPLICATION PRIOR 11.0.1.1261 P20240304/12.1.2.172 ENTERPRISE MANAGER WEB INTERFACE IMPROPER AUTHENTICATION

CVE-2024-29849 : VEERAM BACKUP & REPLICATION PRIOR 11.0.1.1261 P20240304/12.1.2.172 ENTERPRISE MANAGER WEB INTERFACE IMPROPER AUTHENTICATION

Description Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface. References

CVE-2024-36011 : LINUX KERNEL UP TO 6.6.30/6.8.9 BLUETOOTH HCI_LE_BIG_SYNC_ESTABLISHED_EVT NULL POINTER DEREFERENCE

CVE-2024-36011 : LINUX KERNEL UP TO 6.6.30/6.8.9 BLUETOOTH HCI_LE_BIG_SYNC_ESTABLISHED_EVT NULL POINTER DEREFERENCE

Description In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HCI: Fix potential null-ptr-deref Fix potential null-ptr-deref in