CVE-2020-8966: Cross Site Scripting (XSS) flaws found in Tiki-Wiki CMS software
There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages of Tiki-Wiki Groupware. Tiki-Wiki CMS all versions through 20.0 allows malicious users to cause the injection of malicious code fragments (scripts) into a legitimate web page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tiki-Wiki CMSto a version that resolves this vulnerability.Fixed in 21.0
Event History
Frequently Asked Questions
What is the severity of CVE-2020-8966?
CVE-2020-8966 has a medium severity level due to the potential for cross-site scripting attacks.
How do I fix CVE-2020-8966?
To fix CVE-2020-8966, upgrade to Tiki-Wiki CMS version 21.0 or later, which addresses this vulnerability.
What does CVE-2020-8966 affect?
CVE-2020-8966 affects all versions of Tiki-Wiki CMS and groupware up to version 20.0.
What type of vulnerability is CVE-2020-8966?
CVE-2020-8966 is classified as an improper neutralization of script-related HTML tags in a web page, commonly known as basic XSS.
Who can exploit CVE-2020-8966?
Malicious users can exploit CVE-2020-8966 to inject harmful script code into legitimate web pages of Tiki-Wiki CMS.