CVE-2011-4452 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 2.3% (pctl 83)
Patch early
A public exploit exists.
Description
Cross-site request forgery (CSRF) vulnerability in the AdminUsers component in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to hijack the authentication of administrators for requests that remove arbitrary user accounts via a delete operation, as demonstrated by an {{image}} action.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 2.3% — more likely to be exploited than 83% of all CVEs |
| Weakness | CWE-352 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-09-05 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| wikkawiki | wikkawiki |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | WikkaWiki 1.3.2 - Multiple Vulnerabilities | 2011-11-30 |
References
- http://wush.net/trac/wikka/changeset/1819
- http://wush.net/trac/wikka/changeset/1832
- http://wush.net/trac/wikka/ticket/1097
- http://wush.net/trac/wikka/ticket/1098
- http://wush.net/trac/wikka/changeset/1819
- http://wush.net/trac/wikka/changeset/1832
- http://wush.net/trac/wikka/ticket/1097
- http://wush.net/trac/wikka/ticket/1098
→ the Explorer · watch your stack · NVD