SQL Injection Vulnerability in Tiki by Tiki Wiki Software
CVE-2018-20719
8.8HIGH
What is CVE-2018-20719?
Tiki before version 17.2 contains a vulnerability in the user task component that allows for SQL Injection through the 'show_history' parameter in the tiki-user_tasks.php script. Attackers could exploit this flaw to manipulate database queries, potentially leading to unauthorized data access or integrity compromise.