Show filters
154 Total Results
Displaying 91-100 of 154
Sort by:
Attacker Value
Unknown

CVE-2018-7290

Disclosure Date: March 09, 2018 (last updated November 26, 2024)
Cross Site Scripting (XSS) exists in Tiki before 12.13, 15.6, 17.2, and 18.1.
0
Attacker Value
Unknown

CVE-2018-7304

Disclosure Date: February 21, 2018 (last updated November 26, 2024)
Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd|' /C calc'!A0" payload during User Creation.
0
Attacker Value
Unknown

CVE-2018-7303

Disclosure Date: February 21, 2018 (last updated November 26, 2024)
The Calendar component in Tiki 17.1 allows HTML injection.
0
Attacker Value
Unknown

CVE-2018-7302

Disclosure Date: February 21, 2018 (last updated November 26, 2024)
Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.
0
Attacker Value
Unknown

CVE-2018-7188

Disclosure Date: February 16, 2018 (last updated November 26, 2024)
An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with a malicious SVG image, related to lib/filegals/filegallib.php.
0
Attacker Value
Unknown

CVE-2016-7394

Disclosure Date: February 06, 2018 (last updated November 26, 2024)
tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie.
0
Attacker Value
Unknown

CVE-2017-14924

Disclosure Date: September 30, 2017 (last updated November 26, 2024)
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with an IMG element, related to tiki-assignuser.php.
0
Attacker Value
Unknown

CVE-2017-14925

Disclosure Date: September 30, 2017 (last updated November 26, 2024)
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an administrator opens a wiki page with an IMG element, related to tiki-objectpermissions.php. For example, an attacker could assign administrator privileges to every unauthenticated user of the site.
0
Attacker Value
Unknown

CVE-2017-9145

Disclosure Date: June 26, 2017 (last updated November 26, 2024)
TikiFilter.php in Tiki Wiki CMS Groupware 12.x through 16.x does not properly validate the imgsize or lang parameter to prevent XSS.
0
Attacker Value
Unknown

CVE-2017-9305

Disclosure Date: May 31, 2017 (last updated November 26, 2024)
lib/core/TikiFilter/PreventXss.php in Tiki Wiki CMS Groupware 16.2 allows remote attackers to bypass the XSS filter via padded zero characters, as demonstrated by an attack on tiki-batch_send_newsletter.php.
0