Impact
A remote attacker can cause a denial of service by exploiting a flaw in the media_upload_xhr() function within Dokuwiki’s media.php module. The vulnerability is reflected by resource exhaustion and potential memory exhaustion weaknesses, as identified by CWE-400 and CWE-770. When triggered, the request leads the application to become unresponsive, disrupting access for all users without compromising data confidentiality or integrity.
Affected Systems
Dokuwiki DokuWiki version 2025-05-14b is susceptible. No other versions are listed as affected in the available data.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests low exploitation probability. The vulnerability is not currently catalogued in the CISA KEV list. It is inferred that the attack vector is a remote HTTP request targeting the media_upload_xhr endpoint; no authentication prerequisites are stated, so a publicly accessible endpoint is likely sufficient. Because the conditions are easily met and the denial of service has wide impact, operators should consider rapid mitigation.
OpenCVE Enrichment