CVE-2015-2172Improper Access Control in Dokuwiki

Severity
6.5MEDIUMNVD
EPSS
1.8%
top 17.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 30
Latest updateMay 14

Description

DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to gain privileges and add or delete ACL rules via a request to the XMLRPC API.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 8.0 | Impact: 6.4

Affected Packages3 packages

debiandebian/dokuwiki< dokuwiki 0.0.20140929.d-1 (bookworm)
NVDdokuwiki/dokuwiki2014-05-052014-05-05d+1
Debiandokuwiki/dokuwiki< 0.0.20140929.d-1+3

🔴Vulnerability Details

2
GHSA
GHSA-8xqm-cgj8-jqmr: DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to2022-05-14
OSV
CVE-2015-2172: DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to2015-03-30

📋Vendor Advisories

1
Debian
CVE-2015-2172: dokuwiki - DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permi...2015

💬Community

4
Bugzilla
CVE-2015-5277 glibc: data corruption while reading the NSS files database2015-09-14
Bugzilla
CVE-2015-2172 dokuwiki: privilege escalation in RPC API [fedora-all]2015-03-02
Bugzilla
CVE-2015-2172 dokuwiki: privilege escalation in RPC API2015-03-02
Bugzilla
CVE-2015-2172 dokuwiki: privilege escalation in RPC API [epel-all]2015-03-02