CVE-2018-7302

Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.
References
Configurations

Configuration 1

cpe:2.3:a:tiki:tiki:17.1:*:*:*:*:*:*:*

Information

Published : 2018-02-21 08:29

Updated : 2018-03-12 03:35


NVD link : CVE-2018-7302

Mitre link : CVE-2018-7302

Products Affected
No products.
CWE