Cross-Site Scripting Vulnerability in Tiki Software by Tiki Wiki
CVE-2020-16131

6.1MEDIUM

Key Information:

Vendor

Tiki

Status
Vendor
CVE Published:
3 August 2020

What is CVE-2020-16131?

The XSS vulnerability found in Tiki software occurs due to inadequate input sanitization in the file lib/core/TikiFilter/PreventXss.php. Specifically, the regex used does not appropriately account for certain special characters, leading to potential exploitation by attackers to inject malicious scripts. This vulnerability affects all Tiki versions prior to 21.2, posing risks to web applications utilizing Tiki, as it could allow unauthorized users to execute scripts in the context of another user's session.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.