vendor:
Tiki Wiki CMS Groupware
by:
7.5
CVSS
HIGH
HTML-injection
79
CWE
Product Name: Tiki Wiki CMS Groupware
Affected Version From: Tiki Wiki CMS Groupware version 8.1
Affected Version To: Tiki Wiki CMS Groupware version 8.1
Patch Exists: NO
Related CWE:
CPE: a:tikiwiki:tiki_wiki_cms_groupware:8.1
Platforms Tested: Firefox 7.01
HTML-injection vulnerability in Tiki Wiki CMS Groupware
The application fails to properly sanitize user-supplied input, allowing attacker-supplied HTML and script code to run in the context of the affected browser. This can lead to the theft of cookie-based authentication credentials or control over how the site is rendered to the user.
Mitigation:
Apply proper input validation and sanitization to user-supplied input.