Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-7304

Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd|' /C calc'!A0" payload during User Creation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 63.9%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2018-7304
  • Tiki » Tiki » Version: 17.1
    cpe:2.3:a:tiki:tiki:17.1


Contact Us

Shodan ® - All rights reserved