Cross-site scripting (XSS) vulnerability in Tiki Wiki CMS Groupware 6 LTS before 6.13LTS, 9 LTS before 9.7LTS, 10.x before 10.4, and 11.x before 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| tikiwiki/tiki-manager(Packagist) | 6.0 | 6.13 | N/A |
| tikiwiki/tiki-manager(Packagist) | 9.0 | 9.7 | N/A |
| tikiwiki/tiki-manager(Packagist) | 10.0 | 10.4 | N/A |
| tikiwiki/tiki-manager(Packagist) | 11.0 | 11.1 | N/A |
CVSS Metrics