CVE-2018-15474
NONE EPSS 87.1%
Published Sep 7, 20187y ago · Modified Jun 17, 20262w ago
Published Sep 7, 2018 7y ago
Last Modified Jun 17, 2026 2w ago
Description
CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier allows remote attackers to exfiltrate sensitive data and to execute arbitrary code via a value that is mishandled in a CSV export. NOTE: the vendor has stated "this is not a security problem in DokuWiki.
Threat Intelligence
EPSS Exploit Probability
87.1% percentile
Exploit & Patch Status
Public Exploit Known
No Patch Available
Weaknesses 1
CWE-1236
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| dokuwiki | dokuwiki | * | ≤2018-04-22a |
References 4
- github.com https://github.com/splitbrain/dokuwiki/issues/2450
- seclists.org https://seclists.org/fulldisclosure/2018/Sep/4
- patreon.com https://www.patreon.com/posts/unfixed-security-21250652
- sec-consult.com https://www.sec-consult.com/en/blog/advisories/dokuwiki-csv-formula-injection-vulnerability/
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.