Описание
An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed by the Supplier because this is the intentional behavior when the product is configured for self-registration (a non-default feature). The supplier also notes that there is no configuration migration scenario that would result in the self-registration being enabled without the administrators knowledge.
A flaw was found in DokuWiki. A remote attacker can create an account through the registration function. This occurs when the DokuWiki instance is configured to allow self-registration, which is not the default setting. This could lead to the creation of unauthorized user accounts.
Отчет
This flaw in DokuWiki is rated as Low impact because it only affects instances configured for self-registration, which is not the default setting in Red Hat deployments. An attacker could create unauthorized user accounts if this non-default feature is enabled.
Меры по смягчению последствий
To mitigate this issue, ensure that the self-registration feature in DokuWiki is disabled if not explicitly required. This can typically be controlled within the DokuWiki configuration settings. Consult the DokuWiki documentation for specific instructions on managing user registration settings. If the DokuWiki service is reloaded or restarted after configuration changes, verify the setting has taken effect.
Дополнительная информация
Статус:
EPSS
3.7 Low
CVSS3
Связанные уязвимости
An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed by the Supplier because this is the intentional behavior when the product is configured for self-registration (a non-default feature). The supplier also notes that there is no configuration migration scenario that would result in the self-registration being enabled without the administrators knowledge.
An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed by the Supplier because this is the intentional behavior when the product is configured for self-registration (a non-default feature). The supplier also notes that there is no configuration migration scenario that would result in the self-registration being enabled without the administrators knowledge.
An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote atta ...
An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to execute arbitrary code via the register function in inc/auth.php
EPSS
3.7 Low
CVSS3