First published: Wed Oct 22 2014(Updated: )
The ajax_mediadiff function in DokuWiki before 2014-05-05a allows remote attackers to access arbitrary images via a crafted namespace in the ns parameter.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
DokuWiki | <=2013-12-08 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8762 has a medium severity rating due to its potential for remote unauthorized access to sensitive images.
To fix CVE-2014-8762, update DokuWiki to the latest version released after 2014-05-05a.
DokuWiki versions before 2014-05-05a are affected by CVE-2014-8762.
CVE-2014-8762 allows remote attackers to access arbitrary images, potentially exposing sensitive information.
If an update cannot be performed, consider restricting access to the DokuWiki installation to trusted users only.