Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1oN2pjLXBnMnItbXFqNM4AAe6a
Tiki Wiki CMS Groupware Cross-site scripting (XSS) vulnerability
Cross-site scripting (XSS) vulnerability in Tiki Wiki CMS Groupware 6 LTS before 6.13LTS, 9 LTS before 9.7LTS, 10.x before 10.4, and 11.x before 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Permalink: https://github.com/advisories/GHSA-h7jc-pg2r-mqj4JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oN2pjLXBnMnItbXFqNM4AAe6a
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 2 years ago
Updated: 9 months ago
CVSS Score: 4.7
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Identifiers: GHSA-h7jc-pg2r-mqj4, CVE-2013-4714
References:
- https://nvd.nist.gov/vuln/detail/CVE-2013-4714
- http://info.tiki.org/article221-New-Versions-of-all-supported-versions-of-Tiki-Wiki-CMS-Groupware
- http://jvn.jp/en/jp/JVN81813850/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2013-000099
- https://tiki.org/article401-New-Versions-of-all-supported-versions-of-Tiki-Wiki-CMS-Groupware
- https://github.com/advisories/GHSA-h7jc-pg2r-mqj4
Affected Packages
packagist:tikiwiki/tiki-manager
Dependent packages: 0Dependent repositories: 0
Downloads: 766 total
Affected Version Ranges: >= 11.0, < 11.1, >= 10.0, < 10.4, >= 9.0, < 9.7, >= 6.0, < 6.13
Fixed in: 11.1, 10.4, 9.7, 6.13
All affected versions:
All unaffected versions: