CVE-2015-2172: Medium severity dokuwiki vulnerability
Published Mar 30, 2015
·Updated
DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to gain privileges and add or delete ACL rules via a request to the XMLRPC API.
Affected Software
2 affected components
DokuWiki DokuWiki>=2014-05-05<2014-05-05d
DokuWiki DokuWiki>=2014-09-29<2014-09-29c
Event History
Mar 30, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2172?
CVE-2015-2172 is classified as a high severity vulnerability due to its potential to allow unauthorized privilege escalation.
2
How do I fix CVE-2015-2172?
To fix CVE-2015-2172, upgrade DokuWiki to a version later than 2014-09-29c.
3
Who is affected by CVE-2015-2172?
CVE-2015-2172 affects users of DokuWiki versions before 2014-05-05d and 2014-09-29c.
4
What type of attack does CVE-2015-2172 enable?
CVE-2015-2172 enables remote authenticated users to gain unauthorized privileges by manipulating ACL rules.
5
Is there a workaround for CVE-2015-2172?
There is no specific workaround for CVE-2015-2172; updating to the patched version is recommended.