CVE-2017-14925: CSRF
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an administrator opens a wiki page with an IMG element, related to tiki-objectpermissions.php. For example, an attacker could assign administrator privileges to every unauthenticated user of the site.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14925?
CVE-2017-14925 has a moderate severity rating due to its potential impact on global permissions in Tiki applications.
How do I fix CVE-2017-14925?
To fix CVE-2017-14925, upgrade your Tiki installation to versions 12.12 LTS, 15.5 LTS, 16.3, or 17.1 or later.
What versions of Tiki are affected by CVE-2017-14925?
CVE-2017-14925 affects Tiki versions 12.0 to 12.11, 15.0 to 15.4, and 16.0 to 16.2.
Can CVE-2017-14925 be exploited without user interaction?
CVE-2017-14925 requires user interaction, as it exploits authenticated users opening a specially crafted wiki page.
What type of vulnerability is CVE-2017-14925?
CVE-2017-14925 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.