PT-2015-5644 · Dokuwiki · Dokuwiki
Hartwork
·
Published
2015-03-05
·
Updated
2019-02-05
·
CVE-2015-2172
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
DokuWiki versions before 2014-05-05d and before 2014-09-29c
Description
The issue allows remote authenticated users to gain privileges and add or delete ACL rules via a request to the "XMLRPC API".
Recommendations
For versions before 2014-05-05d and before 2014-09-29c, update to a version that properly checks permissions for the ACL plugins to prevent privilege escalation.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dokuwiki