vendor:
Personal Wiki, Team Wiki
by:
Unknown
7.5
CVSS
HIGH
Cross-Site Scripting (XSS), Arbitrary File Upload, Information Disclosure
79 (XSS), 434 (File Upload), 200 (Information Disclosure)
CWE
Product Name: Personal Wiki, Team Wiki
Affected Version From: Personal Wiki 1.14, Team Wiki 1.14
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:portili:personal_wiki:1.14, cpe:/a:portili:team_wiki:1.14
Platforms Tested: Unknown
Unknown
Portili Personal and Team Wiki Multiple Vulnerabilities
Attackers can exploit these issues to obtain sensitive information, steal cookie-based authentication information, upload arbitrary files to the affected computer, and execute arbitrary script code in the context of the browser.
Mitigation:
Apply security patches or updates provided by the vendor. Avoid uploading files from untrusted sources. Regularly monitor the application for any suspicious activity.