Total vulnerabilities in the database
Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain administrator privileges if an administrator opens a wiki page and moves the mouse pointer over a modified link or thumb image.
Software | From | Fixed in |
---|---|---|
tiki / tikiwiki_cms/groupware | 18.0 | 18.2 |
tiki / tikiwiki_cms/groupware | 15.0 | 15.7 |
tiki / tikiwiki_cms/groupware | 12.0 | 12.14 |