CVE-2018-15474: Critical severity dokuwiki vulnerability
DISPUTED CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier allows remote attackers to exfiltrate sensitive data and to execute arbitrary code via a value that is mishandled in a CSV export. NOTE: the vendor has stated "this is not a security problem in DokuWiki."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-15474?
CVE-2018-15474 is considered a medium severity vulnerability related to CSV injection.
How do I fix CVE-2018-15474?
To fix CVE-2018-15474, update DokuWiki to a version later than 2018-04-22a.
What type of attack can be executed through CVE-2018-15474?
CVE-2018-15474 allows remote attackers to exfiltrate sensitive data and execute arbitrary code via CSV export mishandling.
Which versions of DokuWiki are affected by CVE-2018-15474?
CVE-2018-15474 affects DokuWiki versions up to and including 2018-04-22a.
Is CVE-2018-15474 a confirmed vulnerability?
CVE-2018-15474 is disputed, with discussions indicating potential weaknesses but controversy over its severity.