VDB

GCVE-110-MAGEIA-2015-118

GCVE-110-MAGEIA-2015-118
Advisory Published
Vulnetix · Advisory published March 27, 2015
DokuWiki before 20140929d is vulnerable to a cross-site scripting (XSS) issue in the user manager. The user's details were not properly escaped in the user manager's edit form. This allows a registered user to edit her own name (using the change profile option) to include malicious JavaScript code. The code is executed when a super user tries to edit the user via the user manager

Affected Products

VendorProductVersionsPlatforms
Mageiacmake0 (affected), 3.0.2-1.mga5 (unaffected)
Mageiadokuwiki20140929-1.4.mga4 (unaffected), 0 (affected), 0 (affected), 20140929-1.4.mga4 (unaffected)

Browse GCVE Records

74,557 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›