CVE-2011-4551

Cross-site scripting (XSS) vulnerability in tiki-cookie-jar.php in TikiWiki CMS/Groupware before 8.2 and LTS before 6.5 allows remote attackers to inject arbitrary web script or HTML via arbitrary parameters.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
VendorProductVersion
tikitikiwiki_cms\/groupware
𝑥
≤ 8.1
tikitikiwiki_cms\/groupware
2.2
tikitikiwiki_cms\/groupware
3.0
tikitikiwiki_cms\/groupware
3.1
tikitikiwiki_cms\/groupware
3.2
tikitikiwiki_cms\/groupware
3.3
tikitikiwiki_cms\/groupware
3.4
tikitikiwiki_cms\/groupware
3.5
tikitikiwiki_cms\/groupware
4.0
tikitikiwiki_cms\/groupware
4.1
tikitikiwiki_cms\/groupware
4.2
tikitikiwiki_cms\/groupware
5.0
tikitikiwiki_cms\/groupware
5.1
tikitikiwiki_cms\/groupware
5.2
tikitikiwiki_cms\/groupware
5.3
tikitikiwiki_cms\/groupware
6.0
tikitikiwiki_cms\/groupware
6.1
tikitikiwiki_cms\/groupware
6.2
tikitikiwiki_cms\/groupware
7.0
tikitikiwiki_cms\/groupware
7.1
tikitikiwiki_cms\/groupware
7.2
tikitikiwiki_cms\/groupware
8.0
tikitikiwiki_cms\/groupware
𝑥
≤ 6.3
𝑥
= Vulnerable software versions