CVE-2023-3440805.06.2023, 02:15DokuWiki before 2023-04-04a allows XSS via RSS titles.Cross-site ScriptingEnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST5.4 MEDIUMNETWORKLOWLOWCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NmitreCNA------CVEADP------CISA-ADPADP5.4 MEDIUMNETWORKLOWLOWCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NBase ScoreCVSS 3.xEPSS ScorePercentile: 54%VendorProductVersiondokuwikidokuwiki𝑥< 2023-04-04a𝑥= Vulnerable software versionsDebian ReleasesDebian ProductCodenamedokuwikibullseyeno-dsabusterno-dsabookworm0.0.20220731.a-2fixedsid2024-02-06b+dfsg-1fixedtrixie2024-02-06b+dfsg-1fixedUbuntu ReleasesUbuntu ProductCodenamedokuwikioracularnot-affectednoblenot-affectedmanticnot-affectedlunarignoredkineticignoredjammyneeds-triagefocalneeds-triagebionicneeds-triagexenialneeds-triagetrustyignoredKnown Exploits!https://huntr.dev/bounties/c6119106-1a5c-464c-94dd-ee7c5d0bece0/https://huntr.dev/bounties/c6119106-1a5c-464c-94dd-ee7c5d0bece0/Common Weakness EnumerationCWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.Referenceshttps://github.com/dokuwiki/dokuwiki/compare/release-2023-04-04...release-2023-04-04ahttps://github.com/dokuwiki/dokuwiki/pull/3967https://huntr.dev/bounties/c6119106-1a5c-464c-94dd-ee7c5d0bece0/https://www.github.com/splitbrain/dokuwiki/commit/53df38b0e4465894a67a5890f74a6f5f82e827dehttps://github.com/dokuwiki/dokuwiki/compare/release-2023-04-04...release-2023-04-04ahttps://github.com/dokuwiki/dokuwiki/pull/3967https://huntr.dev/bounties/c6119106-1a5c-464c-94dd-ee7c5d0bece0/https://www.github.com/splitbrain/dokuwiki/commit/53df38b0e4465894a67a5890f74a6f5f82e827de