Cross-site scripting (XSS) vulnerability in tiki-view_forum_thread.php in TikiWiki 1.9.0 through 1.9.2 allows remote attackers to inject arbitrary web script or HTML via the topics_offset parameter.
| Software | From | Fixed in |
|---|---|---|
| tiki / tikiwiki_cms/groupware | 1.9.0 | 1.9.0.x |
| tiki / tikiwiki_cms/groupware | 1.9.2 | 1.9.2.x |
| tiki / tikiwiki_cms/groupware | 1.9.1 | 1.9.1.x |