Home
MEDIUM: 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NDefault status
unaffected
All versions (custom) before version 28
affected
Description
Tiki Wiki CMS – CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
All versions (custom) before version 28
Credits
Aviv Vinograzki - Peer Security LTD
References
www.gov.il/en/Departments/faq/cve_advisories