First published: Sat Sep 30 2017(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an administrator opens a wiki page with an IMG element, related to tiki-objectpermissions.php. For example, an attacker could assign administrator privileges to every unauthenticated user of the site.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tiki Wiki CMS Groupware | =12.0 | |
Tiki Wiki CMS Groupware | =12.1 | |
Tiki Wiki CMS Groupware | =12.2 | |
Tiki Wiki CMS Groupware | =12.3 | |
Tiki Wiki CMS Groupware | =12.4 | |
Tiki Wiki CMS Groupware | =12.5 | |
Tiki Wiki CMS Groupware | =12.6 | |
Tiki Wiki CMS Groupware | =12.7 | |
Tiki Wiki CMS Groupware | =12.8 | |
Tiki Wiki CMS Groupware | =12.9 | |
Tiki Wiki CMS Groupware | =12.10 | |
Tiki Wiki CMS Groupware | =12.11 | |
Tiki Wiki CMS Groupware | =15.0 | |
Tiki Wiki CMS Groupware | =15.1 | |
Tiki Wiki CMS Groupware | =15.2 | |
Tiki Wiki CMS Groupware | =15.3 | |
Tiki Wiki CMS Groupware | =15.4 | |
Tiki Wiki CMS Groupware | =16.0 | |
Tiki Wiki CMS Groupware | =16.1 | |
Tiki Wiki CMS Groupware | =16.2 | |
Tiki Wiki CMS Groupware | =17.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14925 has a moderate severity rating due to its potential impact on global permissions in Tiki applications.
To fix CVE-2017-14925, upgrade your Tiki installation to versions 12.12 LTS, 15.5 LTS, 16.3, or 17.1 or later.
CVE-2017-14925 affects Tiki versions 12.0 to 12.11, 15.0 to 15.4, and 16.0 to 16.2.
CVE-2017-14925 requires user interaction, as it exploits authenticated users opening a specially crafted wiki page.
CVE-2017-14925 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.