{"id":"GHSA-v9j2-q4q5-cxh4","summary":"No CSRF protection on the password change form","details":"### Impact\nIt's possible for forge an URL that, when accessed by an admin, will reset the password of any user in XWiki.\n\n### Patches\nThe problem has been patched in XWiki 12.10.5, 13.2RC1.\n\n### Workarounds\nIt's possible to apply the patch manually by modifying the `register_macros.vm` template like in https://github.com/xwiki/xwiki-platform/commit/0a36dbcc5421d450366580217a47cc44d32f7257.\n\n### References\nhttps://jira.xwiki.org/browse/XWIKI-18315\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [Jira XWiki](https://jira.xwiki.org)\n* Email us at [security ML](mailto:security@xwiki.org)\n","aliases":["CVE-2021-32730"],"modified":"2026-07-08T06:29:36.691468443Z","published":"2021-07-02T19:19:13Z","database_specific":{"nvd_published_at":"2021-07-01T18:15:00Z","cwe_ids":["CWE-352"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-07-02T16:41:31Z"},"references":[{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-v9j2-q4q5-cxh4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-32730"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/commit/0a36dbcc5421d450366580217a47cc44d32f7257"},{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-18315"}],"affected":[{"package":{"name":"org.xwiki.platform:xwiki-platform-administration-ui","ecosystem":"Maven","purl":"pkg:maven/org.xwiki.platform/xwiki-platform-administration-ui"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"12.10.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/07/GHSA-v9j2-q4q5-cxh4/GHSA-v9j2-q4q5-cxh4.json"}},{"package":{"name":"org.xwiki.platform:xwiki-platform-administration-ui","ecosystem":"Maven","purl":"pkg:maven/org.xwiki.platform/xwiki-platform-administration-ui"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13.0"},{"fixed":"13.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/07/GHSA-v9j2-q4q5-cxh4/GHSA-v9j2-q4q5-cxh4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"}]}