First published: Mon Oct 28 2024(Updated: )
Tiki through 27.0 allows users who have certain permissions to insert a "Create a Wiki Pages" stored XSS payload in the description.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tiki Wiki CMS Groupware | <=27.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-51506 is classified as a stored XSS vulnerability affecting Tiki versions up to 27.0.
To fix CVE-2024-51506, upgrade Tiki to the latest version beyond 27.0 where the vulnerability is addressed.
CVE-2024-51506 allows authenticated users with certain permissions to inject and execute malicious scripts in the wiki pages.
Any Tiki installation running version 27.0 or earlier, particularly those allowing user-generated content, is affected by CVE-2024-51506.
Yes, CVE-2024-51506 can potentially lead to data breaches if an attacker exploits the stored XSS to execute harmful scripts that compromise user data.