Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with an IMG element, related to tiki-assignuser.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Tiki 跨站请求伪造漏洞
Vulnerability Description
Tiki是Tiki软件社区的一套开源的内容管理和门户应用程序,它可用于创建Web应用程序、门户网站、企业内部网、外联网等。 Tiki中存在跨站请求伪造漏洞。远程攻击者可借助IMG元素利用该漏洞获取管理员权限。以下版本受到影响:Tiki 16.3之前的版本,17.1之前的17.x版本,12.12 LTS之前的12 LTS版本,15.5 LTS之前的15 LTS版本。
CVSS Information
N/A
Vulnerability Type
N/A