CVE-2017-9305
Dashboard / Vulnerabilities / CVE-2017-9305
CVE-2017-9305
Published: 31 May 2017Last Modified: 8 Jul 2026
Summary:
Details: lib/core/TikiFilter/PreventXss.php in Tiki Wiki CMS Groupware 16.2 allows remote attackers to bypass the XSS filter via padded zero characters, as demonstrated by an attack on tiki-batch_send_newsletter.php.
References: https://github.com/tikiorg/tiki/commit/6c016e8f066d2f404b18eaa1af7fa0c7a9651ccd, https://www.cdxy.me/?p=763
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- d027438011aacbe400083c31d44b4b5519043113
Fixed -None
Affected versions
16.2
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
