CVE-2016-9646
MEDIUMikiwiki < 3.20161229 - Commit Metadata Forgery via CGI::FormBuilder->field Method
Title source: llmDescription
ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla's CVE-2014-1572), which can be abused to lead to commit metadata forgery.
References (4)
Core 4
Core References
Third Party Advisory vendor-advisory
x_refsource_debian
https://www.debian.org/security/2017/dsa-3760
Issue Tracking, Third Party Advisory x_refsource_confirm
https://security-tracker.debian.org/tracker/CVE-2016-9646
Vendor Advisory x_refsource_confirm
https://ikiwiki.info/security/#cve-2016-9646
Third Party Advisory mailing-list
x_refsource_mlist
https://marc.info/?l=oss-security&m=148304341511854&w=2
Scores
CVSS v3
5.3
EPSS
0.0118
EPSS Percentile
63.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Details
CWE
CWE-287
Status
published
Products (4)
debian/debian_linux
7.0
debian/debian_linux
8.0
debian/debian_linux
9.0
ikiwiki/ikiwiki
< 3.20161229
Published
Apr 13, 2018
Tracked Since
Feb 18, 2026