An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed by the Supplier because this is the i…
Critical CVSS 9.8
Summary
An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed by the Supplier because this is the intentional behavior when the product is configured for self-registration (a non-default feature). The supplier also notes that there is no configuration migration scenario that would result in the self-registration being enabled without the administrators knowledge.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://gist.github.com/KyrieKlay/3260f4eeea025f2cd1daa7eb1360c5a1
- https://github.com/dokuwiki/dokuwiki
- https://github.com/dokuwiki/dokuwiki/issues/4682
- https://gist.github.com/KyrieKlay/3260f4eeea025f2cd1daa7eb1360c5a1
Timeline
- nvd_ingest NVD