Description

A cross-site request forgery (CSRF) vulnerability exists in DokuWiki version 2012-01-25 Angua. The vulnerability in doku.php allows remote attackers to hijack the authentication of administrators and perform unauthorized actions, such as adding new user accounts.

Impact

An attacker can trick an authenticated administrator into visiting a crafted page, which silently creates new user accounts with arbitrary privileges. This can lead to privilege escalation and unauthorized access to the wiki.

Solution

Upgrade to DokuWiki 2012-10-13 Adora Belle or later.

References