First published: Mon Dec 30 2024(Updated: )
Tiki Wiki CMS – CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Credit: cna@cyber.gov.il
Affected Software | Affected Version | How to fix |
---|---|---|
Tiki Wiki CMS Groupware |
Upgrade to version 28 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-47918 has a medium severity rating due to its potential for cross-site scripting attacks.
To fix CVE-2024-47918, ensure that your Tiki Wiki CMS is updated to the latest version where the XSS vulnerability has been patched.
CVE-2024-47918 can facilitate cross-site scripting (XSS) attacks, allowing an attacker to inject malicious scripts into web pages viewed by users.
CVE-2024-47918 affects all versions of Tiki Wiki CMS prior to the release containing the security fix.
Yes, if exploited, CVE-2024-47918 can lead to unauthorized access to user data through malicious script execution.