CVE-2015-2172 — Improper Access Control in Dokuwiki
Severity
6.5MEDIUMNVD
EPSS
1.8%
top 17.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 30
Latest updateMay 14
Description
DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to gain privileges and add or delete ACL rules via a request to the XMLRPC API.
CVSS vector
AV:N/AC:L/C:P/I:P/A:PExploitability: 8.0 | Impact: 6.4
Affected Packages3 packages
🔴Vulnerability Details
2GHSA▶
GHSA-8xqm-cgj8-jqmr: DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to↗2022-05-14
OSV▶
CVE-2015-2172: DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to↗2015-03-30
📋Vendor Advisories
1Debian▶
CVE-2015-2172: dokuwiki - DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permi...↗2015