CVE-2018-7302
21.02.2018, 20:29
Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.
Vendor | Product | Version |
---|---|---|
tiki | tiki | 17.1 |
𝑥
= Vulnerable software versions
Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.
Vendor | Product | Version |
---|---|---|
tiki | tiki | 17.1 |