CVE-2024-51507
CVE-2024-51507 is a stored XSS (Cross-Site Scripting) vulnerability found in Tiki versions up to 27.0. The flaw allows users with specific permissions to inject malicious JavaScript code within the "Name" field of the "Create/Edit External Wiki" feature. Despite the relatively low SVRS of 30, the potential for malicious code execution exists when other users interact with the crafted wiki page. While the CVSS score is 0, the presence of the "In The Wild" tag warrants attention. Successful exploitation can lead to session hijacking, defacement, or redirection to phishing sites. Although the SVRS indicates lower immediate risk, remediating this vulnerability is crucial to prevent potential escalation by threat actors. The vulnerability is classified as CWE-79, highlighting the common nature of XSS flaws.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.