Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Rubikscraft

#31707of 53,633
8.1Total CVSS
Vulnerabilities · 1
PT-2022-16164
8.1
2022-02-22
Wiki.Js · Wiki.Js · CVE-2022-23654
**Name of the Vulnerable Software and Affected Versions** Wiki.js (affected versions not specified) **Description** The issue affects Wiki.js, a wiki app built on Node.js, where an authenticated user with write access on a restricted set of paths can update a page outside the allowed paths. This is possible by specifying a different target page ID while keeping the path intact, due to incorrect access control checks against user-provided values instead of the actual path associated with the page ID. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.