Impact
LeafWiki versions 0.1.0 through 0.10.0 allow an authenticated user to modify their own account role through the user update API. This flaw can be used to promote a regular user, such as viewer, to an administrator, resulting in full control over the wiki. The weakness is a classic privilege escalation problem identified as CWE-269. Because the attacker must first have a valid account, the attack requires authentication but does not need additional privileges.
Affected Systems
The vulnerability affects the self‑hosted wiki software LeafWiki from vendor perber. All releases from version 0.1.0 up to 0.10.0 are affected. Users with an authenticated LeafWiki account are directly impacted until they apply an update to version 0.10.1 or later.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score is unavailable, but the flaw is not listed in the CISO KEV catalog, suggesting it has not yet been widely exploited. Because exploitation requires a legitimate account, instances that restrict registration and use only trusted users face lower practical risk, while open‑registration deployments are at higher risk. The attack vector is internal based on authenticated use of the user update API.
OpenCVE Enrichment