CVE-2024-51508: XSS
Tiki through 27.0 allows users who have certain permissions to insert a "Create/Edit External Wiki" stored XSS payload in the Index.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-51508?
CVE-2024-51508 is rated as a high severity vulnerability due to the potential for stored cross-site scripting (XSS).
How do I fix CVE-2024-51508?
To fix CVE-2024-51508, upgrade Tiki to version 27.1 or later, where the vulnerability has been addressed.
What types of attacks can CVE-2024-51508 enable?
CVE-2024-51508 can allow attackers to execute arbitrary JavaScript in the user's browser session, potentially leading to data theft or session hijacking.
Who is affected by CVE-2024-51508?
CVE-2024-51508 affects users of Tiki versions up to and including 27.0 who have specific permissions that allow editing external wikis.
What steps should I take if I cannot upgrade Tiki to address CVE-2024-51508?
If immediate upgrades are not possible, restrict access to the affected features and implement input validation to mitigate potential XSS attacks related to CVE-2024-51508.