Remote File Reading Vulnerability in Tiki Wiki CMS by Tiki Software
CVE-2016-10143

7.5HIGH

Key Information:

Vendor

Tiki

Vendor
CVE Published:
20 January 2017

What is CVE-2016-10143?

A flaw in Tiki Wiki CMS version 15.2 allows an attacker to exploit a crafted pathname in a banner URL field, which could enable unauthorized reading of arbitrary files on the targeted system. This exposure can lead to significant information leakage and potentially compromise system integrity. Users and administrators of affected versions are highly encouraged to apply patches or updates to secure their systems.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.