CVE-2023-34408
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Jun 5, 2023
Updated: Jan 8, 2025
CWE ID 79
Summary
CVE-2023-34408 is a newly disclosed vulnerability in DokuWiki versions prior to 2023-04-04a. This issue permits Cross-Site Scripting (XSS) attacks through maliciously crafted RSS titles. An attacker can inject malicious scripts into a DokuWiki page by manipulating the RSS title field, posing a serious security risk. Successful exploitation can lead to information disclosure or unauthorized actions on the affected system. Users are encouraged to update their DokuWiki installations to the latest version to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- DokuWiki