CVE-2017-12583: XSS
Published Aug 6, 2017
·Updated
DokuWiki through 2017-02-19b has XSS in the at parameter (aka the DATEAT variable) to doku.php.
Affected Software
1 affected component
DokuWiki DokuWiki<=2017-02-19b
Event History
Aug 6, 2017
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12583?
CVE-2017-12583 has a medium severity rating due to its potential for cross-site scripting (XSS) exploitation.
2
How do I fix CVE-2017-12583?
To fix CVE-2017-12583, upgrade DokuWiki to a version newer than 2017-02-19b.
3
What software is affected by CVE-2017-12583?
CVE-2017-12583 affects DokuWiki versions up to and including 2017-02-19b.
4
What type of vulnerability is CVE-2017-12583?
CVE-2017-12583 is a cross-site scripting (XSS) vulnerability in DokuWiki.
5
Is CVE-2017-12583 easy to exploit?
CVE-2017-12583 can be exploited easily if an attacker can manipulate the 'at' parameter in DokuWiki.