Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Some forms with the parameter geo_zoomlevel_to_found_location in Tiki Wiki CMS 12.x before 12.10 LTS, 15.x before 15.3 LTS, and 16.x before 16.1 don't have the input sanitized, related to tiki-setup.php and article_image.php. The impact is XSS.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Tiki Wiki CMS 跨站脚本漏洞
Vulnerability Description
Tiki Wiki CMS是Tiki软件社区的一套开源的内容管理和门户应用程序,它可用于创建Web应用程序、门户网站、企业内部网、外联网等。 Tiki Wiki CMS中带有‘geo_zoomlevel_to_found_location’参数的表格中存在跨站脚本漏洞,该漏洞源于程序没有过滤输入。远程攻击者可利用该漏洞注入任意Web脚本或HTML。以下版本受到影响:Tiki Wiki CMS 12.10 LTS之前的12.x版本,15.3 LTS之前的15.x版本,16.1之前的16.x版本。
CVSS Information
N/A
Vulnerability Type
N/A