Логотип exploitDog
bind:CVE-2017-14925
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-14925

Количество 3

Количество 3

nvd логотип

CVE-2017-14925

больше 8 лет назад

Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an administrator opens a wiki page with an IMG element, related to tiki-objectpermissions.php. For example, an attacker could assign administrator privileges to every unauthenticated user of the site.

CVSS3: 8
EPSS: Низкий
debian логотип

CVE-2017-14925

больше 8 лет назад

Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tik ...

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-6hrv-qqj8-pvx9

больше 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an administrator opens a wiki page with an IMG element, related to tiki-objectpermissions.php. For example, an attacker could assign administrator privileges to every unauthenticated user of the site.

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-14925

Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an administrator opens a wiki page with an IMG element, related to tiki-objectpermissions.php. For example, an attacker could assign administrator privileges to every unauthenticated user of the site.

CVSS3: 8
0%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-14925

Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tik ...

CVSS3: 8
0%
Низкий
больше 8 лет назад
github логотип
GHSA-6hrv-qqj8-pvx9

Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an administrator opens a wiki page with an IMG element, related to tiki-objectpermissions.php. For example, an attacker could assign administrator privileges to every unauthenticated user of the site.

CVSS3: 8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу