Vulnerability Description
Tiki before 21.2 allows XSS because [\s\/"\'] is not properly considered in lib/core/TikiFilter/PreventXss.php.
CVSS Score
6.1
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tiki | Tiki | < 21.2 |
Related Weaknesses (CWE)
References
- https://gitlab.com/tikiwiki/tiki/-/commit/d12d6ea7b025d3b3f81c8a71063fe9f89e0c4bThird Party Advisory
- https://tiki.org/NewsVendor Advisory
- https://gitlab.com/tikiwiki/tiki/-/commit/d12d6ea7b025d3b3f81c8a71063fe9f89e0c4bThird Party Advisory
- https://tiki.org/NewsVendor Advisory
FAQ
What is CVE-2020-16131?
CVE-2020-16131 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Tiki before 21.2 allows XSS because [\s\/"\'] is not properly considered in lib/core/TikiFilter/PreventXss.php.
How severe is CVE-2020-16131?
CVE-2020-16131 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-16131?
Check the references section above for vendor advisories and patch information. Affected products include: Tiki Tiki.