CVE-2007-5683: XSS
Multiple cross-site scripting (XSS) vulnerabilities in TikiWiki 1.9.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to the password reminder page (tiki-remindpassword.php), (2) IMG tags in wiki pages, and (3) the localphp parameter to db/tiki-db.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5683?
CVE-2007-5683 is categorized as a medium severity vulnerability due to multiple cross-site scripting (XSS) issues in TikiWiki.
How do I fix CVE-2007-5683?
To fix CVE-2007-5683, upgrade TikiWiki to version 1.9.9 or later, which addresses these XSS vulnerabilities.
What versions of TikiWiki are affected by CVE-2007-5683?
CVE-2007-5683 affects TikiWiki versions 1.9.8.1 and earlier.
What attack vectors does CVE-2007-5683 expose?
CVE-2007-5683 allows attackers to exploit username inputs, IMG tags in wiki pages, and the local_php parameter to inject arbitrary scripts.
Who is impacted by CVE-2007-5683?
Any users of TikiWiki versions 1.9.8.1 and earlier are at risk due to the XSS vulnerabilities outlined in CVE-2007-5683.