First published: Wed Feb 21 2018(Updated: )
Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd|' /C calc'!A0" payload during User Creation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tiki Tiki | =17.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7304 is considered a medium severity vulnerability due to the potential for CSV Injection attacks.
To fix CVE-2018-7304, update to a patched version of Tiki that addresses input validation for special characters.
CVE-2018-7304 enables a CSV Injection attack that can execute commands on the victim's machine.
CVE-2018-7304 specifically affects Tiki version 17.1.
Yes, CVE-2018-7304 can potentially lead to unauthorized access or control over the victim's system.