CVE-2007-4554: XSS
Published Aug 28, 2007
·Updated
Cross-site scripting (XSS) vulnerability in tiki-remindpassword.php in Tikiwiki (aka Tiki CMS/Groupware) 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: this issue might be related to CVE-2006-2635.7.
Affected Software
1 affected component
Tiki Wiki CMS Groupware=1.9.7
Event History
Aug 28, 2007
CVE Published
12:17 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4554?
CVE-2007-4554 has a moderate severity level due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2007-4554?
To fix CVE-2007-4554, upgrade Tikiwiki to version 1.9.8 or later, which addresses the vulnerability.
3
What systems are affected by CVE-2007-4554?
CVE-2007-4554 specifically affects Tikiwiki version 1.9.7.
4
What kind of attack can be executed using CVE-2007-4554?
CVE-2007-4554 enables remote attackers to execute cross-site scripting attacks through the username parameter.
5
Is CVE-2007-4554 related to any other vulnerabilities?
CVE-2007-4554 may be related to CVE-2006-2635.7, indicating similar underlying issues.