CVE-2010-0288
EPSS 27.2%
Description
A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to gain privileges and access closed wikis by editing current ACL statements, as demonstrated in the wild in January 2010.
How to fix CVE-2010-0288
To remediate CVE-2010-0288, upgrade the affected package to a fixed version below.
- Debian/dokuwiki—upgrade to 0.0.20090214b-3.1 or later
Is CVE-2010-0288 being exploited?
Moderate — EPSS is 27.2%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 0.0.20090214b-3.1