PT-2014-8716 · Dokuwiki · Dokuwiki

Michitux

·

Published

2014-10-22

·

Updated

2015-09-10

·

CVE-2014-8761

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions DokuWiki versions prior to 2014-05-05
Description The issue allows remote attackers to access arbitrary images through a media file details ajax call because it only checks for access to the root namespace.
Recommendations For versions prior to 2014-05-05, update to a version that includes the fix for this issue to prevent unauthorized access to images.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-8761
DSA-3059-1
MGASA-2014-0438

Affected Products

Dokuwiki