CVE-2018-20719: SQL Injection
Published Jan 15, 2019
·Updated
In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-usertasks.php showhistory parameter.
Affected Software
1 affected component
Tiki Wiki CMS Groupware<17.2
Event History
Jan 15, 2019
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20719?
CVE-2018-20719 is classified as a medium severity vulnerability due to its potential for SQL Injection attacks.
2
How do I fix CVE-2018-20719?
To fix CVE-2018-20719, upgrade to Tiki version 17.2 or later.
3
What component of Tiki is affected by CVE-2018-20719?
The user task component of Tiki is affected by CVE-2018-20719.
4
What type of vulnerability is CVE-2018-20719?
CVE-2018-20719 is a SQL Injection vulnerability that allows attackers to manipulate database queries.
5
Which versions of Tiki are vulnerable to CVE-2018-20719?
Tiki versions prior to 17.2 are vulnerable to CVE-2018-20719.