mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-10 11:57:37 +02:00
650 B
650 B
CVE-2018-7302
Description
Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.
POC
Reference
- https://websecnerd.blogspot.in/2018/01/tiki-wiki-cms-groupware-17.html
- https://websecnerd.blogspot.in/2018/01/tiki-wiki-cms-groupware-17.html
Github
No PoCs found on GitHub currently.