CVE-2011-4455: XSS
Multiple cross-site scripting vulnerabilities in Tiki 7.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) tiki-adminsystem.php, (2) tiki-pagehistory.php, (3) tiki-removepage.php, or (4) tiki-renamepage.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4455?
CVE-2011-4455 is considered a high-severity vulnerability due to its potential for remote exploitation through cross-site scripting.
How do I fix CVE-2011-4455?
To fix CVE-2011-4455, upgrade Tiki to version 7.3 or later, which addresses the identified cross-site scripting vulnerabilities.
What are the affected components in CVE-2011-4455?
CVE-2011-4455 affects tiki-admin_system.php, tiki-pagehistory.php, tiki-removepage.php, and tiki-rename_page.php in Tiki versions 7.2 and earlier.
Can CVE-2011-4455 affect my website's users?
Yes, CVE-2011-4455 can allow remote attackers to execute arbitrary web scripts or HTML, potentially compromising user data and security.
Is CVE-2011-4455 a common vulnerability in Tiki?
CVE-2011-4455 is one of the multiple identified cross-site scripting vulnerabilities in Tiki, highlighting a significant security concern prior to version 7.3.