Impact
Wiki.js through 2.5.314 does not enforce path separators when evaluating START and END page rules, allowing a user granted access to a folder to view or modify any page that shares that folder’s literal prefix. The result is an authorization bypass that gives attackers unwarranted confidentiality and integrity access to unrelated pages, potentially enabling data exfiltration or malicious content injection.
Affected Systems
The vulnerability affects Requarks Wiki.js, versions up to and including 2.5.314. Users deploying any of these releases are at risk unless mitigated or updated.
Risk and Exploitability
The CVSS score of 8.6 signals high severity. The EPSS score is less than 1%, indicating a low current exploitation probability, and the flaw is not listed in the CISA KEV catalog. Attackers may exploit the flaw by sending crafted requests to a Wiki.js instance that they can reach; while the description does not specify an authentication requirement, the bypass occurs regardless of the specific access level assigned to the user’s folder, suggesting that an authenticated user or an attacker with network access to the site can benefit from the flaw.
OpenCVE Enrichment