CVE-2019-15314: XSS
Published Aug 22, 2019
·Updated
tiki/tiki-uploadfile.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-downloadfile.php?display&fileId= URI.
Affected Software
1 affected component
Tiki Wiki CMS Groupware=18.4
Event History
Aug 22, 2019
CVE Published
via MITRE·12:15 PM
Data Sourced
via MITRE·12:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-15314?
CVE-2019-15314 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2019-15314?
To fix CVE-2019-15314, upgrade Tiki to the latest version that addresses this vulnerability.
3
What does CVE-2019-15314 affect?
CVE-2019-15314 affects Tiki version 18.4, allowing remote attackers to upload malicious JavaScript code.
4
What type of attack can be executed through CVE-2019-15314?
CVE-2019-15314 allows remote attackers to execute JavaScript code by uploading it through a vulnerable file upload mechanism.
5
Is CVE-2019-15314 a known issue in older Tiki versions?
Yes, CVE-2019-15314 is a known vulnerability in Tiki version 18.4 and may be present in earlier versions.