Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

Editing restriction bypass for git revert

Disclosure Date: April 10, 2018 (last updated November 26, 2024)
The fix for ikiwiki for CVE-2016-10026 was incomplete resulting in editing restriction bypass for git revert when using git versions older than 2.8.0. This has been fixed in 3.20161229.
0
Attacker Value
Unknown

CVE-2016-10026

Disclosure Date: February 13, 2017 (last updated November 26, 2024)
ikiwiki 3.20161219 does not properly check if a revision changes the access permissions for a page on sites with the git and recentchanges plugins and the CGI interface enabled, which allows remote attackers to revert certain changes by leveraging permissions to change the page before the revision was made.
0