First published: Fri Sep 07 2018(Updated: )
** DISPUTED ** CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier allows remote attackers to exfiltrate sensitive data and to execute arbitrary code via a value that is mishandled in a CSV export. NOTE: the vendor has stated "this is not a security problem in DokuWiki."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DokuWiki | <=2018-04-22a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15474 is considered a medium severity vulnerability related to CSV injection.
To fix CVE-2018-15474, update DokuWiki to a version later than 2018-04-22a.
CVE-2018-15474 allows remote attackers to exfiltrate sensitive data and execute arbitrary code via CSV export mishandling.
CVE-2018-15474 affects DokuWiki versions up to and including 2018-04-22a.
CVE-2018-15474 is disputed, with discussions indicating potential weaknesses but controversy over its severity.