Cross-Site Scripting Vulnerability in Tiki Software by Tiki Wiki
CVE-2020-16131
6.1MEDIUM
What is CVE-2020-16131?
The XSS vulnerability found in Tiki software occurs due to inadequate input sanitization in the file lib/core/TikiFilter/PreventXss.php. Specifically, the regex used does not appropriately account for certain special characters, leading to potential exploitation by attackers to inject malicious scripts. This vulnerability affects all Tiki versions prior to 21.2, posing risks to web applications utilizing Tiki, as it could allow unauthorized users to execute scripts in the context of another user's session.