Sheela Sarva

4 exploits Active since Mar 2026
CVE-2024-46878 NOMISEC MEDIUM WRITEUP
Tiki < 27.1 - Cross-Site Scripting via tiki-editpage.php Page Parameter
A Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 and earlier. This vulnerability allows attackers to execute arbitrary JavaScript code via a crafted payload, leading to potential access to sensitive information or unauthorized actions.
CVSS 5.4
CVE-2024-46879 NOMISEC MEDIUM WORKING POC
Tiki < 21.11 - Reflected Cross-Site Scripting via tiki-admin_system.php zipPath Parameter
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the POST request data zipPath of tiki-admin_system.php in Tiki version 21.2. This vulnerability allows attackers to execute arbitrary JavaScript code via a crafted payload, leading to potential access to sensitive information or unauthorized actions.
CVSS 5.4
CVE-2024-46878 WRITEUP MEDIUM WRITEUP
Tiki < 27.1 - Cross-Site Scripting via tiki-editpage.php Page Parameter
A Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 and earlier. This vulnerability allows attackers to execute arbitrary JavaScript code via a crafted payload, leading to potential access to sensitive information or unauthorized actions.
CVSS 5.4
CVE-2024-46879 WRITEUP MEDIUM WORKING POC
Tiki < 21.11 - Reflected Cross-Site Scripting via tiki-admin_system.php zipPath Parameter
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the POST request data zipPath of tiki-admin_system.php in Tiki version 21.2. This vulnerability allows attackers to execute arbitrary JavaScript code via a crafted payload, leading to potential access to sensitive information or unauthorized actions.
CVSS 5.4