REDHAT-BUG-717146: XSS
It was found that DokuWiki's RSS embedding mechanism did not properly escape user-provided links. An attacker could use this flaw to conduct cross-site scripting (XSS) attacks, potentially leading to arbitrary JavaScript code execution.
References: [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=631818 [2] http://www.certa.ssi.gouv.fr/site/CERTA-2011-AVI-366/CERTA-2011-AVI-366.html [3] http://www.freelists.org/post/dokuwiki/Hotfix-Release-20110525a-Rincewind
Solution: This issue has been addressed in upstream "2011-05-25 Rincewind" release: [4] http://www.dokuwiki.org/changes
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-717146?
REDHAT-BUG-717146 is classified as a moderate severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix REDHAT-BUG-717146?
To fix REDHAT-BUG-717146, update DokuWiki to a version newer than 2011-05-25 where this vulnerability has been addressed.
What type of vulnerability is REDHAT-BUG-717146?
REDHAT-BUG-717146 is a cross-site scripting (XSS) vulnerability affecting DokuWiki's RSS embedding mechanism.
What can attackers achieve through REDHAT-BUG-717146?
Attackers exploiting REDHAT-BUG-717146 can execute arbitrary JavaScript code in the context of the user's browser.
Which versions of DokuWiki are affected by REDHAT-BUG-717146?
DokuWiki versions up to 2011-05-25 are affected by REDHAT-BUG-717146.