CVE-2018-14849: XSS
Published Aug 13, 2018
·Updated
Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes, related to lib/core/WikiParser/OutputLink.php and lib/parser/parserlib.php.
Affected Software
3 affected components
Tiki Wiki CMS Groupware>=12.0<12.14
Tiki Wiki CMS Groupware>=15.0<15.7
Tiki Wiki CMS Groupware>=18.0<18.2
Event History
Aug 13, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-14849?
The severity of CVE-2018-14849 is considered medium due to its potential for XSS attacks.
2
How do I fix CVE-2018-14849?
To fix CVE-2018-14849, upgrade Tiki to version 12.14, 15.7, or 18.2 or later.
3
What software is affected by CVE-2018-14849?
CVE-2018-14849 affects Tiki versions prior to 18.2, 15.7, and 12.14.
4
What type of vulnerability is CVE-2018-14849?
CVE-2018-14849 is an XSS vulnerability that arises from inadequate sanitization of link attributes.
5
Are there any specific files linked to CVE-2018-14849?
CVE-2018-14849 is related to issues in the files lib/core/WikiParser/OutputLink.php and lib/parser/parserlib.php.