CVE-2010-0288: High severity DokuWiki DokuWiki vulnerability
A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to gain privileges and access closed wikis by editing current ACL statements, as demonstrated in the wild in January 2010.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0288?
CVE-2010-0288 is rated as medium severity due to its potential to allow unauthorized access to closed wikis.
How do I fix CVE-2010-0288?
To resolve CVE-2010-0288, update DokuWiki to version 2009-12-25b or later, which addresses this vulnerability.
What kind of attacks does CVE-2010-0288 enable?
CVE-2010-0288 allows remote attackers to gain elevated privileges and access restricted areas of the wiki.
Which versions of DokuWiki are affected by CVE-2010-0288?
CVE-2010-0288 affects all versions of DokuWiki prior to version 2009-12-25b.
Is there a patch available for CVE-2010-0288?
Yes, the patch for CVE-2010-0288 is included in the DokuWiki update to version 2009-12-25b.