PatchSiren cyber security CVE debrief
CVE-2016-10143 Tiki CVE debrief
CVE-2016-10143 is a Tiki Wiki CMS 15.2 vulnerability that can let a remote attacker read arbitrary files on the target system by supplying a crafted pathname in a banner URL field. NVD classifies the issue as high severity with confidentiality impact, and the record indicates no privileges or user interaction are required.
- Vendor
- Tiki
- Product
- Tikiwiki Cms/groupware
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-20
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-20
- Advisory updated
- 2026-05-13
Who should care
Administrators and security owners running Tiki Wiki CMS 15.2, especially any internet-facing deployment or instance where banner content can be edited or processed.
Technical summary
The NVD record describes a network-reachable file-read condition in Tiki Wiki CMS 15.2 where a crafted pathname in a banner URL field can expose arbitrary files. NVD maps the issue to CWE-200 and rates it CVSS 3.0 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), indicating a remotely exploitable confidentiality impact without authentication or user interaction.
Defensive priority
High
Recommended defensive actions
- Apply the vendor patch or updated release referenced in the Tiki issue tracker and SourceForge patch record.
- Review any use of banner URL fields and remove or validate inputs that can influence filesystem path handling.
- Restrict administrative access to Tiki configuration and content-management functions where practical.
- Check exposed Tiki Wiki CMS 15.2 instances for suspicious requests involving banner URL values or unexpected file access patterns.
- If you cannot immediately patch, reduce exposure by limiting network access to the application until remediation is complete.
Evidence notes
All statements are based on the supplied NVD record and its listed references. The corpus identifies Tiki Wiki CMS 15.2 as the affected CPE, describes the issue as arbitrary file read through a crafted pathname in a banner URL field, and lists CWE-200 with CVSS 3.0 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. The record was published on 2017-01-20 and marked modified on 2026-05-13. No Exploited in the Wild/KEV data was supplied.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-10143 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-10143
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-10143 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-10143
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://dev.tiki.org/item6174
[email protected] - Permissions Required
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://sourceforge.net/p/tikiwiki/code/60308/
[email protected] - Issue Tracking, Patch, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.