Multiple cross-site request forgery (CSRF) vulnerabilities in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25c allow remote attackers to hijack the authentication of administrators for requests that modify access control rules, and other unspecified requests, via unknown vectors.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2010-02-15 10:30
Updated : 2019-09-23 11:13
NVD link : CVE-2010-0289
Mitre link : CVE-2010-0289
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
dokuwiki
- dokuwiki