CVE-2018-15474
07.09.2018, 22:29
CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier allows remote attackers to exfiltrate sensitive data and to execute arbitrary code via a value that is mishandled in a CSV export. NOTE: the vendor has stated "this is not a security problem in DokuWiki.Enginsight
Vendor | Product | Version |
---|---|---|
dokuwiki | dokuwiki | 𝑥 ≤ 2018-04-22a |
𝑥
= Vulnerable software versions

Ubuntu Releases
References