CVE-2018-7290: XSS
Published Mar 9, 2018
·Updated
Cross Site Scripting (XSS) exists in Tiki before 12.13, 15.6, 17.2, and 18.1.
Affected Software
4 affected components
Tiki Wiki CMS Groupware>=12.0<12.13
Tiki Wiki CMS Groupware>=15.0<15.6
Tiki Wiki CMS Groupware>=17.0<17.2
Tiki Wiki CMS Groupware=18.0
Remediation
Patch Available
Event History
Mar 9, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-7290?
CVE-2018-7290 is classified as a medium severity vulnerability due to the risk of cross-site scripting (XSS).
2
How do I fix CVE-2018-7290?
To fix CVE-2018-7290, upgrade Tiki to a version later than 12.13, 15.6, 17.2, or 18.1.
3
What type of vulnerability is CVE-2018-7290?
CVE-2018-7290 is a cross-site scripting (XSS) vulnerability.
4
Which versions of Tiki are affected by CVE-2018-7290?
CVE-2018-7290 affects Tiki versions before 12.13, 15.6, 17.2, and 18.1.
5
Is CVE-2018-7290 exploitable remotely?
Yes, CVE-2018-7290 is exploitable remotely as it involves cross-site scripting vulnerabilities.