CVE-2015-2172

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
30/03/2015
Last modified:
12/04/2025

Description

DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to gain privileges and add or delete ACL rules via a request to the XMLRPC API.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dokuwiki:dokuwiki:*:*:*:*:*:*:*:* 2014-05-05 (including) 2014-05-05d (excluding)
cpe:2.3:a:dokuwiki:dokuwiki:*:*:*:*:*:*:*:* 2014-09-29 (including) 2014-09-29c (excluding)