CVE-2021-36551: XSS
TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-calendar.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload under the Add Event module.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36551?
The severity of CVE-2021-36551 is classified as high due to its ability to allow attackers to execute arbitrary web scripts or HTML.
How do I fix CVE-2021-36551?
To fix CVE-2021-36551, you should update TikiWiki to the latest version that addresses this vulnerability.
What component is affected by CVE-2021-36551?
CVE-2021-36551 affects the tiki-calendar.php component of TikiWiki v21.4.
What impact does CVE-2021-36551 have on TikiWiki users?
CVE-2021-36551 allows attackers to exploit the Add Event module to execute malicious scripts, posing a risk to user data and security.
Is there a workaround for CVE-2021-36551?
Currently, the recommended action is to update to the patched version, as no official workaround is available for CVE-2021-36551.