CVE-2024-46879: XSS
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the POST request data zipPath of tiki-adminsystem.php in Tiki version 21.2. This vulnerability allows attackers to execute arbitrary JavaScript code via a crafted payload, leading to potential access to sensitive information or unauthorized actions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46879?
CVE-2024-46879 has a high severity rating due to its potential impact on sensitive information through reflected XSS.
How do I fix CVE-2024-46879?
To fix CVE-2024-46879, upgrade to Tiki version 21.3 or later, which addresses this reflected XSS vulnerability.
What type of vulnerability is CVE-2024-46879?
CVE-2024-46879 is a Reflected Cross-Site Scripting (XSS) vulnerability that exploits the POST request data.
Who is affected by CVE-2024-46879?
CVE-2024-46879 affects users running Tiki version 21.2, allowing attackers to execute arbitrary JavaScript.
What could an attacker achieve with CVE-2024-46879?
An attacker exploiting CVE-2024-46879 could execute arbitrary JavaScript, potentially gaining access to sensitive information or user sessions.