CVE-2017-14924

Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with an IMG element, related to tiki-assignuser.php.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 44%
VendorProductVersion
tikitikiwiki_cms\/groupware
12.0
tikitikiwiki_cms\/groupware
12.1
tikitikiwiki_cms\/groupware
12.2
tikitikiwiki_cms\/groupware
12.3
tikitikiwiki_cms\/groupware
12.4
tikitikiwiki_cms\/groupware
12.5
tikitikiwiki_cms\/groupware
12.6
tikitikiwiki_cms\/groupware
12.7
tikitikiwiki_cms\/groupware
12.8
tikitikiwiki_cms\/groupware
12.9
tikitikiwiki_cms\/groupware
12.10
tikitikiwiki_cms\/groupware
12.11
tikitikiwiki_cms\/groupware
15.0
tikitikiwiki_cms\/groupware
15.1
tikitikiwiki_cms\/groupware
15.2
tikitikiwiki_cms\/groupware
15.3
tikitikiwiki_cms\/groupware
15.4
tikitikiwiki_cms\/groupware
16.0
tikitikiwiki_cms\/groupware
16.1
tikitikiwiki_cms\/groupware
16.2
tikitikiwiki_cms\/groupware
17.0
𝑥
= Vulnerable software versions