CVE-2024-51509
CVE-2024-51509: Stored XSS Vulnerability in Tiki. Tiki versions up to 27.0 are susceptible to a stored cross-site scripting (XSS) vulnerability via the "Modules" feature. Specifically, users with sufficient permissions can inject a malicious payload into the 'Name' field within tiki-admin_modules.php. While the CVSS score is 0, the SVRS of 30 suggests a moderate risk. This means that, while not immediately critical, the vulnerability should be addressed. An attacker could potentially inject malicious scripts into the application. This could allow them to execute arbitrary code in the browsers of other users who access the affected module. Even though the CVSS score is low, XSS vulnerabilities can lead to data theft, session hijacking, or defacement of the website, posing a significant security risk if exploited.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.