Tiki Tikiwiki CMS/Groupware 18.4

CPE Details

Tiki Tikiwiki CMS/Groupware 18.4
18.4
2019-10-23
18h06 +00:00
2019-10-23
18h06 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:tiki:tikiwiki_cms\/groupware:18.4:*:*:*:*:*:*:*

Informations

Vendor

tiki

Product

tikiwiki_cms\/groupware

Version

18.4

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2020-8966 2020-04-01 20h18 +00:00 There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages of Tiki-Wiki Groupware. Tiki-Wiki CMS all versions through 20.0 allows malicious users to cause the injection of malicious code fragments (scripts) into a legitimate web page.
6.5
Medium
CVE-2019-15314 2019-08-22 10h15 +00:00 tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php?display&fileId= URI.
5.4
Medium