PT-2015-5644 · Dokuwiki · Dokuwiki

Hartwork

·

Published

2015-03-05

·

Updated

2019-02-05

·

CVE-2015-2172

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions DokuWiki versions before 2014-05-05d and before 2014-09-29c
Description The issue allows remote authenticated users to gain privileges and add or delete ACL rules via a request to the "XMLRPC API".
Recommendations For versions before 2014-05-05d and before 2014-09-29c, update to a version that properly checks permissions for the ACL plugins to prevent privilege escalation.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-2172
MGASA-2015-0093

Affected Products

Dokuwiki