CVE-2023-34408

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jun 5, 2023
Updated: Jan 8, 2025
CWE ID 79

Summary

CVE-2023-34408 is a newly disclosed vulnerability in DokuWiki versions prior to 2023-04-04a. This issue permits Cross-Site Scripting (XSS) attacks through maliciously crafted RSS titles. An attacker can inject malicious scripts into a DokuWiki page by manipulating the RSS title field, posing a serious security risk. Successful exploitation can lead to information disclosure or unauthorized actions on the affected system. Users are encouraged to update their DokuWiki installations to the latest version to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share