CVE-2011-2510: XSS
Cross-site scripting (XSS) vulnerability in the RSS embedding feature in DokuWiki before 2011-05-25a Rincewind allows remote attackers to inject arbitrary web script or HTML via a link.
Other sources
It was found that DokuWiki's RSS embedding mechanism did not properly escape user-provided links. An attacker could use this flaw to conduct cross-site scripting (XSS) attacks, potentially leading to arbitrary JavaScript code execution.
References: [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=631818 [2] http://www.certa.ssi.gouv.fr/site/CERTA-2011-AVI-366/CERTA-2011-AVI-366.html [3] http://www.freelists.org/post/dokuwiki/Hotfix-Release-20110525a-Rincewind
Solution: This issue has been addressed in upstream "2011-05-25 Rincewind" release: [4] http://www.dokuwiki.org/changes
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2510?
CVE-2011-2510 is classified as a medium-severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2011-2510?
To fix CVE-2011-2510, upgrade DokuWiki to the version released after May 25, 2011.
What does CVE-2011-2510 affect?
CVE-2011-2510 affects multiple versions of DokuWiki prior to 2011-05-25a Rincewind.
Can attackers exploit CVE-2011-2510 remotely?
Yes, attackers can exploit CVE-2011-2510 remotely to inject arbitrary web scripts or HTML.
What is the cause of CVE-2011-2510?
CVE-2011-2510 is caused by DokuWiki's RSS embedding feature not properly escaping user-provided links.