CVE-2024-51507: XSS
Tiki through 27.0 allows users who have certain permissions to insert a "Create/Edit External Wiki" stored XSS payload in the Name.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-51507?
CVE-2024-51507 is classified as a stored Cross-Site Scripting (XSS) vulnerability with significant risk due to potential impacts on user data integrity and application security.
How do I fix CVE-2024-51507?
To fix CVE-2024-51507, update your Tiki software to version 27.1 or later where the vulnerability is patched.
Who is affected by CVE-2024-51507?
CVE-2024-51507 affects Tiki installations up to and including version 27.0 where users have permissions to create or edit external wiki pages.
What causes CVE-2024-51507?
CVE-2024-51507 is caused by improper input validation that allows users to inject malicious scripts into the Name field when creating or editing external wiki entries.
What types of attacks can CVE-2024-51507 enable?
CVE-2024-51507 can enable various attacks including session hijacking, data theft, and manipulation of the behavior of the application for users accessing the affected pages.