{"id":"UBUNTU-CVE-2024-33103","details":"** DISPUTED ** An arbitrary file upload vulnerability in the Media Manager component of DokuWiki 2024-02-06a allows attackers to execute arbitrary code by uploading a crafted SVG file. NOTE: as noted in the 4267 issue reference, there is a position that exploitability can only occur with a misconfiguration of the product.","modified":"2024-04-30T18:15:00Z","published":"2024-04-30T18:15:00Z","withdrawn":"2025-06-23T15:58:13Z","references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-33103"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2024-33103"},{"type":"REPORT","url":"https://github.com/dokuwiki/dokuwiki/issues/4267"}],"affected":[{"package":{"name":"dokuwiki","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/dokuwiki"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.0.20140929.d-1","0.0.20140929.d-1ubuntu1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-33103.json"}},{"package":{"name":"dokuwiki","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/dokuwiki"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.0.20160626.a-2"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-33103.json"}},{"package":{"name":"dokuwiki","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/dokuwiki"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.0.20180422.a-2"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-33103.json"}},{"package":{"name":"dokuwiki","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/dokuwiki"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.0.20180422.a-2.1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-33103.json"}},{"package":{"name":"dokuwiki","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/dokuwiki"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.0.20220731.a-2"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-33103.json"}}],"schema_version":"1.7.3"}