Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-42758 — CVE-2024-42758 - Dokuwiki (indexmenu plugin) - XSS Vulnerability | Kitploit
Tools/GitHubGitHub/1s1ldur/cve-2024-42758
Vulnerability AnalysisWeb Application ExploitationWeb SecurityPapers & ResearchLearning & Education
GitHub1s1ldur/cve-2024-42758

CVE-2024-42758

CVE-2024-42758 - Dokuwiki (indexmenu plugin) - XSS Vulnerability

View Repository
12 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-42758

A Cross-site Scripting (XSS) vulnerability exists in version v2024-01-05 of the indexmenu plugin when is used and enabled in Dokuwiki (Open Source Wiki Engine). A malicious attacker can input XSS payloads for example when creating or editing existing page, to trigger the XSS on Dokuwiki, which is then stored in .txt file (due to nature of how Dokuwiki is designed), which presents stored XSS.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-42758

Vulnerable Dokuwiki page: doku.php?id=[page_name]

Vulnerable Payload:

image

image

image

Discovered by Antun Matija Kriskovic, July 2024

Download Tool