RSS   Vulnerabilities for 'Tikiwiki cms\/groupware'   RSS

2021-10-28
 
CVE-2021-36550

CWE-79
 

 
TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-browse_categories.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload under the Create category module.

 
 
CVE-2021-36551

CWE-79
 

 
TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-calendar.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload under the Add Event module.

 
2020-12-11
 
CVE-2020-29254

CWE-352
 

 
TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected system. An attacker could exploit this vulnerability by persuading a user of the interface to follow a maliciously crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected system with the privileges of the user. These action include allowing attackers to submit their own code through an authenticated user resulting in local file Inclusion. If an authenticated user who is able to edit TikiWiki templates visits an malicious website, template code can be edited.

 
2020-04-01
 
CVE-2020-8966

CWE-79
 

 
There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages of Tiki-Wiki Groupware. Tiki-Wiki CMS all versions through 20.0 allows malicious users to cause the injection of malicious code fragments (scripts) into a legitimate web page.

 
2020-02-12
 
CVE-2013-6022

CWE-79
 

 
A Cross-Site Scripting (XSS) vulnerability exists in Tiki Wiki CMG Groupware 11.0 via the id paraZeroClipboard.swf, which could let a remote malicious user execute arbitrary code.

 
2020-01-15
 
CVE-2011-4336

CWE-79
 

 
Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php.

 

 >>> Vendor: TIKI 4 Products
Tikiwiki cms/groupware
Tikiwiki cms%2fgroupware
TIKI
Tikiwiki cms\/groupware


Copyright 2022, cxsecurity.com

 

Back to Top