The Solr-based search in XWiki discloses the email addresses of users even when obfuscation of email addresses is enabled. To demonstrate the vulnerability, search for objcontent:email* using XWiki's regular search interface.
id: CVE-2023-50720
info:
name: XWiki < 4.10.15 - Email Disclosure
author: ritikchaddha
severi
...