CVE-2018-14850: XSS
Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain administrator privileges if an administrator opens a wiki page and moves the mouse pointer over a modified link or thumb image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-14850?
CVE-2018-14850 has a medium severity rating due to its potential for an authenticated user to exploit stored XSS to gain elevated privileges.
How do I fix CVE-2018-14850?
To fix CVE-2018-14850, upgrade Tiki to versions 18.2, 15.7, or 12.14 or later.
Who is affected by CVE-2018-14850?
CVE-2018-14850 affects authenticated users of Tiki versions prior to 18.2, 15.7, and 12.14.
What type of vulnerability is CVE-2018-14850?
CVE-2018-14850 is categorized as a stored Cross-Site Scripting (XSS) vulnerability.
What can an attacker achieve with CVE-2018-14850?
An attacker can inject malicious JavaScript through modified links or images, which can lead to gaining administrator privileges if exploited.