CVE-2010-1136: High severity Tiki Wiki CMS Groupware vulnerability
The Standard Remember method in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to bypass access restrictions related to "persistent login," probably due to the generation of predictable cookies based on the IP address and User agent in userslib.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1136?
CVE-2010-1136 is considered to have a medium severity as it allows remote attackers to bypass access restrictions on TikiWiki CMS/Groupware.
How do I fix CVE-2010-1136?
To fix CVE-2010-1136, upgrade TikiWiki CMS/Groupware to version 3.5 or later.
Which versions are affected by CVE-2010-1136?
CVE-2010-1136 affects TikiWiki CMS/Groupware versions 3.0 through 3.4.
What impact does CVE-2010-1136 have on TikiWiki users?
CVE-2010-1136 allows attackers to potentially access accounts without permission by exploiting persistent login vulnerabilities.
Is there a workaround for CVE-2010-1136 besides upgrading?
There are no known effective workarounds for CVE-2010-1136, so upgrading is the recommended approach.