Vulnerability Description
CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier allows remote attackers to exfiltrate sensitive data and to execute arbitrary code via a value that is mishandled in a CSV export. NOTE: the vendor has stated "this is not a security problem in DokuWiki.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dokuwiki | Dokuwiki | <= 2018-04-22a |
Related Weaknesses (CWE)
References
- https://github.com/splitbrain/dokuwiki/issues/2450ExploitIssue TrackingThird Party Advisory
- https://seclists.org/fulldisclosure/2018/Sep/4ExploitMailing ListThird Party Advisory
- https://www.patreon.com/posts/unfixed-security-21250652
- https://www.sec-consult.com/en/blog/advisories/dokuwiki-csv-formula-injection-vuExploitThird Party Advisory
- https://github.com/splitbrain/dokuwiki/issues/2450ExploitIssue TrackingThird Party Advisory
- https://seclists.org/fulldisclosure/2018/Sep/4ExploitMailing ListThird Party Advisory
- https://www.patreon.com/posts/unfixed-security-21250652
- https://www.sec-consult.com/en/blog/advisories/dokuwiki-csv-formula-injection-vuExploitThird Party Advisory
FAQ
What is CVE-2018-15474?
CVE-2018-15474 is a vulnerability with a CVSS score of 9.6 (CRITICAL). CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier allows remote attackers to exfiltrate sensitive data and to exe...
How severe is CVE-2018-15474?
CVE-2018-15474 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-15474?
Check the references section above for vendor advisories and patch information. Affected products include: Dokuwiki Dokuwiki.