CVE-2018-7302: XSS
Published Feb 21, 2018
·Updated
Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.
Affected Software
2 affected components
composer/tikiwiki/tiki-manager<=17.1
Tiki tiki=17.1
Event History
Feb 21, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:29 PM
DescriptionSeverityWeaknessAffected Software
May 14, 2022
Advisory Published
03:38 AM
Frequently Asked Questions
1
What is the severity of CVE-2018-7302?
CVE-2018-7302 is rated as a high-severity vulnerability due to its potential for XSS attacks.
2
How do I fix CVE-2018-7302?
To fix CVE-2018-7302, upgrade Tiki to the latest version that mitigates this vulnerability.
3
What are the consequences of exploitation for CVE-2018-7302?
Exploitation of CVE-2018-7302 allows attackers to execute arbitrary JavaScript in the context of the user’s browser.
4
Which versions of Tiki are affected by CVE-2018-7302?
CVE-2018-7302 specifically affects Tiki version 17.1.
5
What kind of attack does CVE-2018-7302 facilitate?
CVE-2018-7302 facilitates Cross-Site Scripting (XSS) attacks through misleading file uploads.