First published: Tue Jan 15 2019(Updated: )
In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tiki Wiki CMS Groupware | <17.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20719 is classified as a medium severity vulnerability due to its potential for SQL Injection attacks.
To fix CVE-2018-20719, upgrade to Tiki version 17.2 or later.
The user task component of Tiki is affected by CVE-2018-20719.
CVE-2018-20719 is a SQL Injection vulnerability that allows attackers to manipulate database queries.
Tiki versions prior to 17.2 are vulnerable to CVE-2018-20719.