CVE-2009-4089

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
29/11/2009
Last modified:
09/04/2025

Description

telepark.wiki 2.4.23 and earlier allows remote attackers to bypass authorization and (1) delete arbitrary pages via a modified pageID parameter to ajax/deletePage.php or (2) delete arbitrary comments via a modified pageID parameter to ajax/deleteComment.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:telepark:telepark.wiki:2.4.23:*:*:*:*:*:*:*