CVE-2011-4452

WikkaWiki 1.3.1 and 1.3.2 - Cross-Site Request Forgery in AdminUsers Component

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-4452. PoCs published by EgiX.

AI-analyzed exploit summary This is a detailed technical analysis of multiple vulnerabilities in WikkaWiki <= 1.3.2, including SQL injection, unrestricted file upload, arbitrary file download/deletion, and remote code execution. The writeup provides proof-of-concept requests and explains the root causes of each vulnerability.

Description

Cross-site request forgery (CSRF) vulnerability in the AdminUsers component in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to hijack the authentication of administrators for requests that remove arbitrary user accounts via a delete operation, as demonstrated by an {{image}} action.

Exploits (1)

exploitdb WRITEUP
by EgiX · textwebappsphp
https://www.exploit-db.com/exploits/18177

This is a detailed technical analysis of multiple vulnerabilities in WikkaWiki <= 1.3.2, including SQL injection, unrestricted file upload, arbitrary file download/deletion, and remote code execution. The writeup provides proof-of-concept requests and explains the root causes of each vulnerability.

Classification
Writeup 100%
Attack Type
Sqli | Info Leak | Auth Bypass | Other
Complexity
Moderate
Reliability
Reliable
Target: WikkaWiki <= 1.3.2
Auth required
Prerequisites: Access to the target WikkaWiki instance · Valid session cookie for authenticated actions
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit, Patch x_refsource_confirm
http://wush.net/trac/wikka/changeset/1832
Exploit x_refsource_confirm
http://wush.net/trac/wikka/ticket/1098
Exploit, Patch x_refsource_confirm
http://wush.net/trac/wikka/changeset/1819
Various Sources x_refsource_confirm
http://wush.net/trac/wikka/ticket/1097

Scores

EPSS 0.0231
EPSS Percentile 81.2%

Details

CWE
CWE-352
Status published
Products (2)
wikkawiki/wikkawiki 1.3.1
wikkawiki/wikkawiki 1.3.2
Published Sep 05, 2012
Tracked Since Feb 18, 2026