PT-2022-16164 · Wiki.Js · Wiki.Js

Rubikscraft

·

Published

2022-02-22

·

Updated

2023-07-24

·

CVE-2022-23654

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Wiki.js (affected versions not specified)
Description The issue affects Wiki.js, a wiki app built on Node.js, where an authenticated user with write access on a restricted set of paths can update a page outside the allowed paths. This is possible by specifying a different target page ID while keeping the path intact, due to incorrect access control checks against user-provided values instead of the actual path associated with the page ID.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23654
GHSA-3CV9-795V-6J7J

Affected Products

Wiki.Js