CVE-2010-0288 describes a privilege escalation vulnerability in DokuWiki versions prior to 2009-12-25b, specifically within the ACL Manager plugin. A typo in the administrator permission check allowed remote attackers to modify existing ACL statements, thereby gaining unauthorized access to restricted wikis. This vulnerability has a CVSS score of 7.5, indicating high severity due to its network-based attack vector, low attack complexity, and potential for partial compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, evidence suggests in-the-wild exploitation in January 2010, and an ExploitDB entry (EDB-11141) confirms exploit code availability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= release_2009-02-14CPE matchmatch criteria | cpe:2.3:a:dokuwiki:dokuwiki:*:*:*:*:*:*:*:* | ||
2004-07-04CPE matchmatch criteria | cpe:2.3:a:dokuwiki:dokuwiki:2004-07-04:*:*:*:*:*:*:* | ||
2004-07-07CPE matchmatch criteria | cpe:2.3:a:dokuwiki:dokuwiki:2004-07-07:*:*:*:*:*:*:* | ||
2004-07-12CPE matchmatch criteria | cpe:2.3:a:dokuwiki:dokuwiki:2004-07-12:*:*:*:*:*:*:* | ||
2004-07-21CPE matchmatch criteria | cpe:2.3:a:dokuwiki:dokuwiki:2004-07-21:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.