vendor:
Tiki Wiki CMS Groupware
by:
Maximilian Barz
9.8
CVSS
CRITICAL
Authentication Bypass
287
CWE
Product Name: Tiki Wiki CMS Groupware
Affected Version From: 21.1
Affected Version To: 21.1
Patch Exists: YES
Related CWE: CVE-2020-15906
CPE: a:tiki_wiki_cms_groupware:tiki_wiki_cms_groupware:21.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux 5.7.0-kali1-amd64
2020
Tiki Wiki CMS Groupware 21.1 – Authentication Bypass
This exploit is for Tiki Wiki CMS Groupware 21.1. It is a PoC for CVE-2020-15906. It uses a request to the tiki-login_scr.php page with the admin username and password to log in as admin. It then sends a request to the tiki-admin.php page to get the admin token. Finally, it sends a request to the tiki-login.php page with the admin username, password, and token to bypass authentication.
Mitigation:
Upgrade to Tiki Wiki CMS Groupware 21.2 or later.