CVE-2017-9305: XSS
lib/core/TikiFilter/PreventXss.php in Tiki Wiki CMS Groupware 16.2 allows remote attackers to bypass the XSS filter via padded zero characters, as demonstrated by an attack on tiki-batchsendnewsletter.php.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9305?
CVE-2017-9305 is classified as a vulnerability that allows remote attackers to bypass the XSS filter in Tiki Wiki CMS Groupware 16.2.
How do I fix CVE-2017-9305?
To fix CVE-2017-9305, you should upgrade to the latest version of Tiki Wiki CMS Groupware that addresses this vulnerability.
What type of attack can be executed using CVE-2017-9305?
CVE-2017-9305 can be exploited to perform cross-site scripting (XSS) attacks by bypassing the XSS filter.
Which version of Tiki Wiki is affected by CVE-2017-9305?
CVE-2017-9305 specifically affects Tiki Wiki CMS Groupware version 16.2.
Is CVE-2017-9305 a local or remote vulnerability?
CVE-2017-9305 is a remote vulnerability that allows attackers to exploit the XSS filter from a remote location.