CVE-2017-14924
Last modified
CVE-2017-14924 is a vulnerability of currently unknown severity. Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with an IMG element, related to tiki-assignuser.php.. EPSS estimates a 0.50% chance of exploitation in the next 30 days.
Description
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with an IMG element, related to tiki-assignuser.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tiki | Tikiwiki Cms\/Groupware | 12.0 |
| Tiki | Tikiwiki Cms\/Groupware | 12.1 |
| Tiki | Tikiwiki Cms\/Groupware | 12.2 |
| Tiki | Tikiwiki Cms\/Groupware | 12.3 |
| Tiki | Tikiwiki Cms\/Groupware | 12.4 |
| Tiki | Tikiwiki Cms\/Groupware | 12.5 |
| Tiki | Tikiwiki Cms\/Groupware | 12.6 |
| Tiki | Tikiwiki Cms\/Groupware | 12.7 |
| Tiki | Tikiwiki Cms\/Groupware | 12.8 |
| Tiki | Tikiwiki Cms\/Groupware | 12.9 |
| Tiki | Tikiwiki Cms\/Groupware | 12.10 |
| Tiki | Tikiwiki Cms\/Groupware | 12.11 |
| Tiki | Tikiwiki Cms\/Groupware | 15.0 |
| Tiki | Tikiwiki Cms\/Groupware | 15.1 |
| Tiki | Tikiwiki Cms\/Groupware | 15.2 |
| Tiki | Tikiwiki Cms\/Groupware | 15.3 |
| Tiki | Tikiwiki Cms\/Groupware | 15.4 |
| Tiki | Tikiwiki Cms\/Groupware | 16.0 |
| Tiki | Tikiwiki Cms\/Groupware | 16.1 |
| Tiki | Tikiwiki Cms\/Groupware | 16.2 |
| Tiki | Tikiwiki Cms\/Groupware | 17.0 |
References
- http://openwall.com/lists/oss-security/2017/09/28/13Mailing List, Third Party Advisory
- https://sourceforge.net/p/tikiwiki/code/63829Patch, Third Party Advisory
- https://tiki.org/article449-Security-and-bug-fix-updates-Tiki-17-1-Tiki-16-3-15-5-and-Tiki-12-12-releasedPatch, Release Notes, Vendor Advisory
- http://openwall.com/lists/oss-security/2017/09/28/13Mailing List, Third Party Advisory
- https://sourceforge.net/p/tikiwiki/code/63829Patch, Third Party Advisory
- https://tiki.org/article449-Security-and-bug-fix-updates-Tiki-17-1-Tiki-16-3-15-5-and-Tiki-12-12-releasedPatch, Release Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-14924?
How severe is CVE-2017-14924?
How do I fix CVE-2017-14924?
Are you affected by CVE-2017-14924?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
