A vulnerability in XWiki's REST API allows unauthenticated users to access attachments list and metadata through the attachments endpoint. This could lead to disclosure of sensitive information stored in attachments metadata.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view