PT-2009-6268 · Telepark · Telepark.Wiki
Published
2009-11-27
·
Updated
2017-08-17
·
CVE-2009-4089
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
telepark.wiki versions 2.4.23 and earlier
Description
The issue allows remote attackers to bypass authorization. This can lead to the deletion of arbitrary pages via a modified
pageID parameter to "ajax/deletePage.php" or the deletion of arbitrary comments via a modified pageID parameter to "ajax/deleteComment.php".Recommendations
For telepark.wiki versions 2.4.23 and earlier, as a temporary workaround, consider restricting access to the "ajax/deletePage.php" and "ajax/deleteComment.php" endpoints until a patch is available. Avoid using the
pageID parameter in these affected endpoints until the issue is resolved.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Telepark.Wiki