CVE-2020-15906: Critical severity tiki wiki cms groupware vulnerability
Published Oct 22, 2020
·Updated
tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.
Affected Software
1 affected component
Tiki tiki>=16.3<21.2
Remediation
Event History
Oct 22, 2020
CVE Published
via MITRE·05:26 PM
Data Sourced
via MITRE·05:26 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-15906?
CVE-2020-15906 has been classified as a moderate severity vulnerability due to its potential to expose administrative privileges.
2
How do I fix CVE-2020-15906?
To fix CVE-2020-15906, upgrade your Tiki installation to version 21.2 or later.
3
What versions of Tiki are affected by CVE-2020-15906?
CVE-2020-15906 affects Tiki versions from 16.3 to 21.1.
4
What is the impact of CVE-2020-15906?
The impact of CVE-2020-15906 is that an attacker can set the admin password to a blank value after multiple invalid login attempts.
5
Is CVE-2020-15906 a remote or local vulnerability?
CVE-2020-15906 is considered a remote vulnerability since it can be exploited through the login interface.