Show filters
97 Total Results
Displaying 21-30 of 97
Sort by:
Attacker Value
Unknown
Editing restriction bypass for git revert
Disclosure Date: April 10, 2018 (last updated November 26, 2024)
The fix for ikiwiki for CVE-2016-10026 was incomplete resulting in editing restriction bypass for git revert when using git versions older than 2.8.0. This has been fixed in 3.20161229.
0
Attacker Value
Unknown
CVE-2018-7290
Disclosure Date: March 09, 2018 (last updated November 26, 2024)
Cross Site Scripting (XSS) exists in Tiki before 12.13, 15.6, 17.2, and 18.1.
0
Attacker Value
Unknown
CVE-2018-7303
Disclosure Date: February 21, 2018 (last updated November 26, 2024)
The Calendar component in Tiki 17.1 allows HTML injection.
0
Attacker Value
Unknown
CVE-2018-7188
Disclosure Date: February 16, 2018 (last updated November 26, 2024)
An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with a malicious SVG image, related to lib/filegals/filegallib.php.
0
Attacker Value
Unknown
CVE-2016-7394
Disclosure Date: February 06, 2018 (last updated November 26, 2024)
tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie.
0
Attacker Value
Unknown
CVE-2017-14924
Disclosure Date: September 30, 2017 (last updated November 26, 2024)
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with an IMG element, related to tiki-assignuser.php.
0
Attacker Value
Unknown
CVE-2017-14925
Disclosure Date: September 30, 2017 (last updated November 26, 2024)
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an administrator opens a wiki page with an IMG element, related to tiki-objectpermissions.php. For example, an attacker could assign administrator privileges to every unauthenticated user of the site.
0
Attacker Value
Unknown
CVE-2017-9145
Disclosure Date: June 26, 2017 (last updated November 26, 2024)
TikiFilter.php in Tiki Wiki CMS Groupware 12.x through 16.x does not properly validate the imgsize or lang parameter to prevent XSS.
0
Attacker Value
Unknown
CVE-2017-9305
Disclosure Date: May 31, 2017 (last updated November 26, 2024)
lib/core/TikiFilter/PreventXss.php in Tiki Wiki CMS Groupware 16.2 allows remote attackers to bypass the XSS filter via padded zero characters, as demonstrated by an attack on tiki-batch_send_newsletter.php.
0
Attacker Value
Unknown
CVE-2016-10026
Disclosure Date: February 13, 2017 (last updated November 26, 2024)
ikiwiki 3.20161219 does not properly check if a revision changes the access permissions for a page on sites with the git and recentchanges plugins and the CGI interface enabled, which allows remote attackers to revert certain changes by leveraging permissions to change the page before the revision was made.
0