@splitbrain@fedi.splitbrain.org
Post #3508272
2026-07-01 10:21 UTC
Okay, after looking into this, the severity level (critical) was not misrepresented, it was total and utter bullshit. The "researcher" merely described a very complicated way to use the user registration form.
Some of the various "security websites" that hope to gain traffic by reposting CVE reports are now leading with the headline "DokuWiki allows remote attackers to execute arbitrary code" - a claim not even the original "researcher" made.
Did I mention that the entire CVE system is a total shit show?
Replies (0)
No replies.