CVE-2018-7303: XSS
Published Feb 21, 2018
·Updated
The Calendar component in Tiki 17.1 allows HTML injection.
Affected Software
1 affected component
Tiki Wiki CMS Groupware=17.1
Event History
Feb 21, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-7303?
CVE-2018-7303 is considered a medium severity vulnerability due to the potential for HTML injection.
2
How do I fix CVE-2018-7303?
To fix CVE-2018-7303, upgrade Tikiwiki CMS/Groupware to version 17.2 or later.
3
What impact does CVE-2018-7303 have on affected systems?
CVE-2018-7303 allows attackers to inject malicious HTML into the Calendar component, potentially leading to cross-site scripting (XSS) attacks.
4
Is CVE-2018-7303 present in versions other than 17.1?
CVE-2018-7303 specifically affects Tiki 17.1 and may not be present in other versions.
5
Which software components are affected by CVE-2018-7303?
CVE-2018-7303 affects the Calendar component of Tikiwiki CMS/Groupware version 17.1.