First published: Tue Apr 30 2024(Updated: )
An arbitrary file upload vulnerability in the Media Manager component of DokuWiki 2024-02-06a allows attackers to execute arbitrary code by uploading a crafted SVG file. NOTE: as noted in the 4267 issue reference, there is a position that exploitability can only occur with a misconfiguration of the product.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DokuWiki |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-33103 has a high severity rating due to its potential to allow arbitrary code execution through file uploads.
To fix CVE-2024-33103, ensure proper configuration of the Media Manager component and restrict SVG file uploads.
CVE-2024-33103 affects DokuWiki version 2024-02-06a and possibly earlier versions if misconfigured.
Exploitation of CVE-2024-33103 generally requires a misconfiguration in the Media Manager settings.
CVE-2024-33103 allows attackers to upload crafted SVG files that can lead to arbitrary code execution.