CVE-2018-7188: XSS
An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with a malicious SVG image, related to lib/filegals/filegallib.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7188?
CVE-2018-7188 is categorized as a high severity XSS vulnerability that can lead to administrator privilege escalation.
How do I fix CVE-2018-7188?
To fix CVE-2018-7188, upgrade Tiki to version 18 or later, which contains the security patch.
Who is affected by CVE-2018-7188?
CVE-2018-7188 affects all authenticated users of Tiki versions prior to 18 who can create or edit wiki pages.
What type of vulnerability is CVE-2018-7188?
CVE-2018-7188 is an HTTP Cross-Site Scripting (XSS) vulnerability that exploits SVG images.
Can CVE-2018-7188 be exploited remotely?
Yes, CVE-2018-7188 can be exploited remotely if an administrator visits a malicious wiki page containing the SVG payload.