Show filters
147 Total Results
Displaying 81-90 of 147
Sort by:
Attacker Value
Unknown
CVE-2018-14849
Disclosure Date: August 13, 2018 (last updated November 27, 2024)
Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes, related to lib/core/WikiParser/OutputLink.php and lib/parser/parserlib.php.
0
Attacker Value
Unknown
CVE-2018-14850
Disclosure Date: August 13, 2018 (last updated November 27, 2024)
Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain administrator privileges if an administrator opens a wiki page and moves the mouse pointer over a modified link or thumb image.
0
Attacker Value
Unknown
CVE-2018-7290
Disclosure Date: March 09, 2018 (last updated November 26, 2024)
Cross Site Scripting (XSS) exists in Tiki before 12.13, 15.6, 17.2, and 18.1.
0
Attacker Value
Unknown
CVE-2018-7304
Disclosure Date: February 21, 2018 (last updated November 26, 2024)
Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd|' /C calc'!A0" payload during User Creation.
0
Attacker Value
Unknown
CVE-2018-7303
Disclosure Date: February 21, 2018 (last updated November 26, 2024)
The Calendar component in Tiki 17.1 allows HTML injection.
0
Attacker Value
Unknown
CVE-2018-7302
Disclosure Date: February 21, 2018 (last updated November 26, 2024)
Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.
0
Attacker Value
Unknown
CVE-2018-7188
Disclosure Date: February 16, 2018 (last updated November 26, 2024)
An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with a malicious SVG image, related to lib/filegals/filegallib.php.
0
Attacker Value
Unknown
CVE-2016-7394
Disclosure Date: February 06, 2018 (last updated November 26, 2024)
tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie.
0
Attacker Value
Unknown
CVE-2017-14924
Disclosure Date: September 30, 2017 (last updated November 26, 2024)
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with an IMG element, related to tiki-assignuser.php.
0
Attacker Value
Unknown
CVE-2017-14925
Disclosure Date: September 30, 2017 (last updated November 26, 2024)
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an administrator opens a wiki page with an IMG element, related to tiki-objectpermissions.php. For example, an attacker could assign administrator privileges to every unauthenticated user of the site.
0