CVE-2024-33103: XSS
An arbitrary file upload vulnerability in the Media Manager component of DokuWiki 2024-02-06a allows attackers to execute arbitrary code by uploading a crafted SVG file. NOTE: as noted in the 4267 issue reference, there is a position that exploitability can only occur with a misconfiguration of the product.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33103?
CVE-2024-33103 has a high severity rating due to its potential to allow arbitrary code execution through file uploads.
How do I fix CVE-2024-33103?
To fix CVE-2024-33103, ensure proper configuration of the Media Manager component and restrict SVG file uploads.
What versions of DokuWiki are affected by CVE-2024-33103?
CVE-2024-33103 affects DokuWiki version 2024-02-06a and possibly earlier versions if misconfigured.
Can CVE-2024-33103 be exploited without misconfiguration?
Exploitation of CVE-2024-33103 generally requires a misconfiguration in the Media Manager settings.
What type of attacks are possible with CVE-2024-33103?
CVE-2024-33103 allows attackers to upload crafted SVG files that can lead to arbitrary code execution.