VulnerabilityModified
CVE-2018-14850
Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain administrator privileges if an administrator opens a wiki page and moves the mouse pointer over a modified link or thumb image.
MEDIUM 5.4EPSS 0.68%
Does this matter?
Lower severity and a low EPSS score (0.68%). Track it; it rarely justifies an emergency change on its own.
Description
Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain administrator privileges if an administrator opens a wiki page and moves the mouse pointer over a modified link or thumb image.
- CVSS 3.0
- 5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.68% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- tiki/tikiwiki cms\/groupware
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2018/08/02/1Mailing List
- http://www.openwall.com/lists/oss-security/2018/08/02/2Mailing List
- https://sourceforge.net/p/tikiwiki/code/66990Third Party Advisory
- http://www.openwall.com/lists/oss-security/2018/08/02/1Mailing List
- http://www.openwall.com/lists/oss-security/2018/08/02/2Mailing List
- https://sourceforge.net/p/tikiwiki/code/66990Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.