Vulnerability Database
Blog
FAQ
Docs
CVE-2023-34408
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2023-34408
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-34408.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-34408
Aliases
BIT-dokuwiki-2023-34408
Related
UBUNTU-CVE-2023-34408
Published
2023-06-05T02:15:09Z
Modified
2025-01-14T11:44:52.732963Z
Severity
5.4 (Medium)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS Calculator
Summary
[none]
Details
DokuWiki before 2023-04-04a allows XSS via RSS titles.
References
https://huntr.dev/bounties/c6119106-1a5c-464c-94dd-ee7c5d0bece0/
https://github.com/dokuwiki/dokuwiki/compare/release-2023-04-04...release-2023-04-04a
https://github.com/dokuwiki/dokuwiki/pull/3967
https://www.github.com/splitbrain/dokuwiki/commit/53df38b0e4465894a67a5890f74a6f5f82e827de
https://security-tracker.debian.org/tracker/CVE-2023-34408
Affected packages
Debian:11
/
dokuwiki
Package
Name
dokuwiki
Purl
pkg:deb/debian/dokuwiki?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Affected versions
0.*
0.0.20180422.a-2.1
0.0.20200729-0.1~bpo11+1
0.0.20200729-0.1
0.0.20220317~gitaeff85c-0.1~exp1
0.0.20220731.a-1
0.0.20220731.a-2
0.0.20220731.a-3
Other
2024-02-06b-0exp1
2024-02-06b-0exp2
2024-02-06b-0exp3
2024-02-06b-0exp4
2024-02-06b+dfsg-0exp1
2024-02-06b+dfsg-0exp2
2024-02-06b+dfsg-1
Ecosystem specific
{ "urgency": "not yet assigned" }
Debian:12
/
dokuwiki
Package
Name
dokuwiki
Purl
pkg:deb/debian/dokuwiki?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0.0.20220731.a-2
Ecosystem specific
{ "urgency": "not yet assigned" }
Debian:13
/
dokuwiki
Package
Name
dokuwiki
Purl
pkg:deb/debian/dokuwiki?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0.0.20220731.a-2
Ecosystem specific
{ "urgency": "not yet assigned" }
Git
/
github.com/splitbrain/dokuwiki
Affected ranges
Type
GIT
Repo
https://github.com/splitbrain/dokuwiki
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Fixed
871aaf69ac1868037618747e232aa177cf2225d8
Affected versions
Other
release-2005-07-01
release-2005-07-13
release-2005-09-19
release-2005-09-22
release-2006-03-05
release-2006-03-09
release-2006-09-28rc
release-2006-10-08rc
release-2006-10-19rc
release-2006-11-06
release-2007-05-24rc
release-2007-06-26
release-2008-03-31rc
release-2008-04-11rc
release-2008-05-04
release-2008-05-05
release-2009-01-26rc
release-2009-01-30rc
release-2009-02-06rc
release-2009-02-14
release-2009-12-02rc
release-2009-12-25
release-2010-10-07rc
release-2010-10-27rc
release-2010-11-07
release-2010-11-07a
release-2011-11-10rc
release-2011_05_25
release-2011_05_25a
release-2012-01-25
release-2012-01-25b
release-2012-10-13
release-2012_09_10rc
release-2013-05-10
release-2013-05-10a
release-2013-10-28rc
release-2013-11-18rc
release-2013-12-08
release-2013_03_06rc
release-2014-05-05
release-2014-05-05a
release-2014-09-29
release-2014-09-29a
release-2014_09_29b
release-2014_09_29c
release-2014_09_29d
release-2015-08-10
release-2015-08-10a
release-2016-06-26
release-2016-06-26a
release-2017-02-19
release-2017-02-19a
release-2017-02-19b
release-2017-02-19c
release-2017-02-19d
release-2017-02-19e
release-2018-04-22
release-2018-04-22a
release-2018-04-22b
release-2018-04-22c
release-2020-06-01rc
release-2020-06-03rc
release-2020-06-09rc
release-2020-07-29
release-2022-06-26rc
release-2022-07-31
release-2022-07-31a
release-2023-04-04
CVE-2023-34408 - OSV