cbcvebase.
CVE-2015-2172
published 2015-03-30

CVE-2015-2172: DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to gain…

PriorityP434medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
2.86%
85.2th percentile
DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to gain privileges and add or delete ACL rules via a request to the XMLRPC API.

Affected

7 ranges
VendorProductVersion rangeFixed in
debiandokuwiki< dokuwiki 0.0.20140929.d-1 (bookworm)dokuwiki 0.0.20140929.d-1 (bookworm)
dokuwikidokuwiki>= 0 < 0.0.20140929.d-10.0.20140929.d-1
dokuwikidokuwiki>= 0 < 0.0.20140929.d-10.0.20140929.d-1
dokuwikidokuwiki>= 0 < 0.0.20140929.d-10.0.20140929.d-1
dokuwikidokuwiki>= 0 < 0.0.20140929.d-10.0.20140929.d-1
dokuwikidokuwiki>= 2014-05-05 < 2014-05-05d2014-05-05d
dokuwikidokuwiki>= 2014-09-29 < 2014-09-29c2014-09-29c

CVSS provenance

nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.