First published: Thu Oct 22 2020(Updated: )
tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tiki Wiki CMS Groupware | >=16.3<21.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15906 has been classified as a moderate severity vulnerability due to its potential to expose administrative privileges.
To fix CVE-2020-15906, upgrade your Tiki installation to version 21.2 or later.
CVE-2020-15906 affects Tiki versions from 16.3 to 21.1.
The impact of CVE-2020-15906 is that an attacker can set the admin password to a blank value after multiple invalid login attempts.
CVE-2020-15906 is considered a remote vulnerability since it can be exploited through the login interface.