CVE-2022-1681: Authentication Bypass Using an Alternate Path or Channel in requarks/wiki
Published May 12, 2022
·Updated
Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can get root user permissions
Affected Software
1 affected component
Requarks Wiki.js<2.5.281
Remediation
Event History
May 12, 2022
CVE Published
via MITRE·07:45 AM
Data Sourced
via MITRE·07:45 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-1681.
2
What is the severity level of CVE-2022-1681?
The severity level of CVE-2022-1681 is critical with a score of 7.2.
3
What is the affected software for CVE-2022-1681?
The affected software is Requarks wiki.js with versions prior to 2.5.281.
4
How can a user exploit CVE-2022-1681?
A user can exploit CVE-2022-1681 to bypass authentication and gain root user permissions.
5
Are there any references related to CVE-2022-1681?
Yes, you can find references for CVE-2022-1681 at the following links: [GitHub](https://github.com/requarks/wiki/commit/78d02dc8e5d103d248e5d7632bf7a6facdf4264c) and [Huntr.dev](https://huntr.dev/bounties/591b11e1-7504-4a96-99c6-08f2b419e767).