CVE-2024-47920
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-47920 is a cross-site scripting (XSS) vulnerability affecting Tiki Wiki CMS. Attackers can exploit this weakness (CWE-79) to inject malicious scripts into web pages generated by the application. Successful exploitation allows attackers to steal user data, conduct unauthorized actions, or redirect users to malicious sites. The vulnerability can be triggered through user-supplied input that is not properly neutralized during the web page generation process. Users are urged to update their Tiki Wiki installations to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.