VDB
Sign up
MEDIUM5.4

GHSA-7f2f-crxg-cpfv

Tiki Wiki CMS XSS Vulnerability

Details

Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/tikiwiki/tiki-manager
Introduced in: 0

No fixed version published yet for tikiwiki/tiki-manager (composer). Pin to a known-safe version or switch to an alternative.

References