CVE-2024-47920

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Dec 30, 2024
CWE ID 79

Summary

CVE-2024-47920 is a cross-site scripting (XSS) vulnerability affecting Tiki Wiki CMS. Attackers can exploit this weakness (CWE-79) to inject malicious scripts into web pages generated by the application. Successful exploitation allows attackers to steal user data, conduct unauthorized actions, or redirect users to malicious sites. The vulnerability can be triggered through user-supplied input that is not properly neutralized during the web page generation process. Users are urged to update their Tiki Wiki installations to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share