CVE-2024-46878: XSS
A Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 and earlier. This vulnerability allows attackers to execute arbitrary JavaScript code via a crafted payload, leading to potential access to sensitive information or unauthorized actions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46878?
CVE-2024-46878 is classified as a high severity Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2024-46878?
To fix CVE-2024-46878, upgrade to Tiki version 26.4 or later, which addresses this vulnerability.
What impact does CVE-2024-46878 have on users?
CVE-2024-46878 allows attackers to execute arbitrary JavaScript, potentially compromising sensitive information or enabling unauthorized actions.
In which software versions is CVE-2024-46878 applicable?
CVE-2024-46878 affects Tiki versions 26.3 and earlier.
How can I determine if my system is vulnerable to CVE-2024-46878?
To determine vulnerability to CVE-2024-46878, check if your Tiki installation is version 26.3 or earlier.