Description: A vulnerability has been reported in TWiki, which can be exploited by malicious people to bypass certain security restrictions.
The vulnerability is caused due to an error in the registration process. This can be exploited to register as an already registered user by changing the action attribute of the form element to the Sandbox web.
Successful exploitation allows a malicious person to gain the privileges of an already registered user (e.g. a user with TWikiAdminGroup privileges), but requires that the "MapUserToWikiName" setting is enabled.
The vulnerability has been reported in the following releases:
* TWikiRelease04x00x02
* TWikiRelease04x00x01
* TWikiRelease04x00x00
Solution: Apply patch (see original advisory).
Provided and/or discovered by: The vendor credits Harald Jörg.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.