MGASA-2015-0118
Dashboard / Vulnerabilities / MGASA-2015-0118
MGASA-2015-0118
Summary: Updated dokuwiki package fixes security vulnerability
Details: DokuWiki before 20140929d is vulnerable to a cross-site scripting (XSS) issue in the user manager. The user's details were not properly escaped in the user manager's edit form. This allows a registered user to edit her own name (using the change profile option) to include malicious JavaScript code. The code is executed when a super user tries to edit the user via the user manager
References: https://advisories.mageia.org/MGASA-2015-0118.html, https://bugs.mageia.org/show_bug.cgi?id=15539, https://github.com/splitbrain/dokuwiki/issues/1081, https://www.dokuwiki.org/changes#release_2014-09-29d_hrun
Affected packages
Package
Name: dokuwiki
Purl: pkg:rpm/mageia/dokuwiki?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
