CVE-2011-4336: XSS
Published Jan 15, 2020
·Updated
Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarfajax.php.
Affected Software
1 affected component
Tiki Wiki CMS Groupware<=7.0
Event History
Jan 15, 2020
CVE Published
via MITRE·01:48 PM
Data Sourced
via MITRE·01:48 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2011-4336?
CVE-2011-4336 is considered a medium severity vulnerability due to its XSS exploit potential.
2
How does CVE-2011-4336 allow XSS attacks?
CVE-2011-4336 allows XSS attacks through the GET 'ajax' parameter in the snarf_ajax.php script.
3
Which versions of Tiki Wiki CMS Groupware are affected by CVE-2011-4336?
CVE-2011-4336 affects Tiki Wiki CMS Groupware versions up to and including 7.0.
4
How can I mitigate CVE-2011-4336 on my website?
To mitigate CVE-2011-4336, you should upgrade Tiki Wiki CMS Groupware to a version later than 7.0 that has patched this vulnerability.
5
Is CVE-2011-4336 a common vulnerability in Tiki Wiki CMS Groupware?
CVE-2011-4336 is a known vulnerability in Tiki Wiki CMS Groupware that exposes users to potential XSS attacks.