CVE-2024-47918: Tiki Wiki CMS – CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Published Dec 30, 2024
·Updated
Tiki Wiki CMS – CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Affected Software
1 affected component
Tiki Wiki CMS
Remediation
Information
Upgrade to version 28 or later
Event History
Dec 30, 2024
CVE Published
via MITRE·09:41 AM
Data Sourced
via MITRE·09:41 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-47918?
CVE-2024-47918 has a medium severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2024-47918?
To fix CVE-2024-47918, ensure that your Tiki Wiki CMS is updated to the latest version where the XSS vulnerability has been patched.
3
What types of attacks can CVE-2024-47918 facilitate?
CVE-2024-47918 can facilitate cross-site scripting (XSS) attacks, allowing an attacker to inject malicious scripts into web pages viewed by users.
4
Which versions of Tiki Wiki CMS are affected by CVE-2024-47918?
CVE-2024-47918 affects all versions of Tiki Wiki CMS prior to the release containing the security fix.
5
Is user data at risk due to CVE-2024-47918?
Yes, if exploited, CVE-2024-47918 can lead to unauthorized access to user data through malicious script execution.