Tiki prima 18.2, 15.7 e 12.14 ha XSS tramite attributi di collegamento, sono collegati lib / core / WikiParser / OutputLink.php e lib / parser / parserlib.php. |
https://sourceforge.net/p/tikiwiki/code/66809 http://www.openwall.com/lists/oss-security/2018/08/02/2 http://www.openwall.com/lists/oss-security/2018/08/02/1 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14849 |
Vulnerabilità: CVE-2018-14849
