Vulnerability record · CVE-2022-23654 · published 22 February 2022
CVE-2022-23654: Requarks wiki.js improper authentication vulnerability
Requarks · Wiki.Js
Wiki.js is a wiki app built on Node.js. In affected versions an authenticated user with write access on a restricted set of paths can update a page outside the allowed paths by specifying a different target page ID while keeping the path intact. The access control incorrectly check the path access against the user-provided values instead of the actual path associated to the page ID. Commit https://github.com/Requarks/wiki/commit/411802ec2f654bb5ed1126c307575b81e2361c6b fixes this vulnerability by checking access control on the path associated with the page ID instead of the user-provided value. When the path is different than the current value, a second access control check is then performed on the user-provided path before the move operation.
Description
Wiki.js is a wiki app built on Node.js. In affected versions an authenticated user with write access on a restricted set of paths can update a page outside the allowed paths by specifying a different target page ID while keeping the path intact. The access control incorrectly check the path access against the user-provided values instead of the actual path associated to the page ID. Commit https://github.com/Requarks/wiki/commit/411802ec2f654bb5ed1126c307575b81e2361c6b fixes this vulnerability by checking access control on the path associated with the page ID instead of the user-provided value. When the path is different than the current value, a second access control check is then performed on the user-provided path before the move operation.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/Requarks/wiki/commit/411802ec2f654bb5ed1126c307575b81e2361c6b | PatchThird Party Advisory |
| https://github.com/Requarks/wiki/security/advisories/GHSA-3cv9-795v-6j7j | PatchThird Party Advisory |
| https://github.com/Requarks/wiki/commit/411802ec2f654bb5ed1126c307575b81e2361c6b | PatchThird Party Advisory |
| https://github.com/Requarks/wiki/security/advisories/GHSA-3cv9-795v-6j7j | PatchThird Party Advisory |
Track CVE-2022-23654 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-23654), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.