CVE-2024-47920: Tiki Wiki CMS – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Published Dec 30, 2024
·Updated
Tiki Wiki CMS – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected Software
1 affected component
Tiki Wiki CMS
Remediation
Information
Upgrade to version 28 or later
Event History
Dec 30, 2024
CVE Published
via MITRE·09:46 AM
Data Sourced
via MITRE·09:46 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-47920?
CVE-2024-47920 is classified as a medium severity vulnerability due to the risk of cross-site scripting (XSS) attacks.
2
How do I fix CVE-2024-47920?
To fix CVE-2024-47920, update to the latest version of Tiki Wiki CMS where the vulnerability has been patched.
3
What are the potential impacts of CVE-2024-47920?
Exploitation of CVE-2024-47920 could allow an attacker to execute arbitrary JavaScript in the context of a user's session.
4
Which versions of Tiki Wiki CMS are affected by CVE-2024-47920?
CVE-2024-47920 affects various versions of Tiki Wiki CMS prior to the security patch that addresses this vulnerability.
5
Who is responsible for addressing CVE-2024-47920?
The responsibility for addressing CVE-2024-47920 lies with the administrators of affected Tiki Wiki CMS installations.