CVE-2010-0289: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25c allow remote attackers to hijack the authentication of administrators for requests that modify access control rules, and other unspecified requests, via unknown vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0289?
CVE-2010-0289 has been classified as a moderate severity vulnerability due to its potential to allow attackers to hijack administrator authentication.
How do I fix CVE-2010-0289?
To fix CVE-2010-0289, upgrade DokuWiki to a version released after December 25, 2009.
What kind of attacks are possible due to CVE-2010-0289?
CVE-2010-0289 allows attackers to perform cross-site request forgery (CSRF) attacks, potentially modifying access control rules.
Which versions of DokuWiki are affected by CVE-2010-0289?
CVE-2010-0289 affects all versions of DokuWiki released before 2009-12-25c.
Is there a workaround for CVE-2010-0289?
While a definitive workaround is not provided, implementing CSRF protections and updating to the latest version is advisable.