{"id":"CVE-2022-23654","summary":"Improper write access check in Requarks/wiki","details":"Wiki.js is a wiki app built on Node.js. In affected versions an authenticated user with write access on a restricted set of paths can update a page outside the allowed paths by specifying a different target page ID while keeping the path intact. The access control incorrectly check the path access against the user-provided values instead of the actual path associated to the page ID. Commit https://github.com/Requarks/wiki/commit/411802ec2f654bb5ed1126c307575b81e2361c6b fixes this vulnerability by checking access control on the path associated with the page ID instead of the user-provided value. When the path is different than the current value, a second access control check is then performed on the user-provided path before the move operation.","aliases":["GHSA-3cv9-795v-6j7j"],"modified":"2026-08-12T03:51:18.716662524Z","published":"2022-02-22T20:05:11Z","database_specific":{"cwe_ids":["CWE-287"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23654.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23654.json"},{"type":"ADVISORY","url":"https://github.com/Requarks/wiki/security/advisories/GHSA-3cv9-795v-6j7j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23654"},{"type":"FIX","url":"https://github.com/Requarks/wiki/commit/411802ec2f654bb5ed1126c307575b81e2361c6b"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/requarks/wiki","events":[{"introduced":"0"},{"fixed":"a3bf1f7916e0964db669cd2aaded56d3fdd9f35d"},{"fixed":"411802ec2f654bb5ed1126c307575b81e2361c6b"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:requarks:wiki.js:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.5.276"}]}}],"versions":["v2.5.275","2.5.274","2.5.272","2.5.268","2.5.264","2.5.260","2.5.255","2.5.254","2.5.219","2.5.214","2.5.201","2.5.197","2.5.191","2.5.170","2.5.159","2.5.144","2.5.136","2.5.132","2.5.126","2.5.121","2.5.117","2.5.105","2.4.107","2.4.105","2.4.75","2.3.77","2.3.72","2.3.71","2.2.51","2.2.50","2.1.113","2.0.12","2.0.1","2.0.0-rc.17","2.0.0-rc.1","2.0.0-beta.303","2.0.0-beta.275","2.0.0-beta.268","2.0.0-beta.267","2.0.0-beta.241","2.0.0-beta.230","2.0.0-beta.208","2.0.0-beta.203","2.0.0-beta.180","2.0.0-beta.174","2.0.0-beta.148","2.0.0-beta.147","2.0.0-beta.115","2.0.0-beta.91","2.0.0-beta.84","2.0.0-beta.68","2.0.0-beta.42","2.0.0-beta.11","v1.0.6","v1.0.5","v1.0.4","v1.0.3","v1.0.0-beta.13","v1.0.0-beta.12","v1.0.0-beta.11","v1.0.0-beta.10","v1.0.0-beta.9","v1.0.0-beta.8","v1.0.0-beta.7","v1.0.0-beta.6","v1.0-beta.5","v1.0-beta.4","v1.0-beta.3","v1.0-beta.2","v1.0-beta.1","v1.0-alpha.7","v1.0-alpha.6","v1.0-alpha.5","v1.0-alpha.4","v1.0-alpha.3","v1.0-alpha.2","v1.0-alpha.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23654.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"}]}