CVE-2018-14850
Last modified
CVE-2018-14850 is a vulnerability of currently unknown severity. Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain administrator privileges if an administrator opens a wiki page and moves the mouse pointer over a modified link or thumb image.. EPSS estimates a 0.68% chance of exploitation in the next 30 days.
Description
Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain administrator privileges if an administrator opens a wiki page and moves the mouse pointer over a modified link or thumb image.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tiki | Tikiwiki Cms\/Groupware | >= 12.0, < 12.14 |
| Tiki | Tikiwiki Cms\/Groupware | >= 15.0, < 15.7 |
| Tiki | Tikiwiki Cms\/Groupware | >= 18.0, < 18.2 |
References
- https://sourceforge.net/p/tikiwiki/code/66990Third Party Advisory
- https://sourceforge.net/p/tikiwiki/code/66990Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-14850?
How severe is CVE-2018-14850?
How do I fix CVE-2018-14850?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-1484IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5…3.7
- CVE-2018-14840uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it…
- CVE-2018-14846The Mondula Multi Step Form plugin before 1.2.8 for WordPres…
- CVE-2018-14847MikroTik RouterOS through 6.42 allows unauthenticated remote…9.1
- CVE-2018-14849Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes…
- CVE-2018-1485IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5…3.1
- CVE-2018-14851exif_process_IFD_in_MAKERNOTE in ext/exif/exif.c in PHP befo…
- CVE-2018-14852Out-of-bounds array access in dhd_rx_frame in drivers/net/wi…
- CVE-2018-14853A NULL pointer dereference in dhd_prot_txdata_write_flush in…
- CVE-2018-14854Buffer overflow in dhd_bus_flow_ring_delete_response in driv…
- CVE-2018-14855Buffer overflow in dhd_bus_flow_ring_flush_response in drive…
- CVE-2018-14856Buffer overflow in dhd_bus_flow_ring_create_response in driv…
Are you affected by CVE-2018-14850?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
