A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin’s use of CGI::FormBuilder, allowing an attacker to bypass authentication via repeated parameters.
[
{
"product": "ikiwiki",
"vendor": "ikiwiki",
"versions": [
{
"status": "affected",
"version": "before 3.20170111"
}
]
}
]