CVE-2018-7304: High severity Tiki tiki vulnerability
Published Feb 21, 2018
·Updated
Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd|' /C calc'!A0" payload during User Creation.
Affected Software
1 affected component
Tiki tiki=17.1
Event History
Feb 21, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-7304?
CVE-2018-7304 is considered a medium severity vulnerability due to the potential for CSV Injection attacks.
2
How do I fix CVE-2018-7304?
To fix CVE-2018-7304, update to a patched version of Tiki that addresses input validation for special characters.
3
What kind of attack is enabled by CVE-2018-7304?
CVE-2018-7304 enables a CSV Injection attack that can execute commands on the victim's machine.
4
Which version of Tiki is affected by CVE-2018-7304?
CVE-2018-7304 specifically affects Tiki version 17.1.
5
Can CVE-2018-7304 lead to unauthorized access?
Yes, CVE-2018-7304 can potentially lead to unauthorized access or control over the victim's system.