PatchSiren

Tiki CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Tiki CVE published 2017-01-20

CVE-2016-10143

CVE-2016-10143 is a Tiki Wiki CMS 15.2 vulnerability that can let a remote attacker read arbitrary files on the target system by supplying a crafted pathname in a banner URL field. NVD classifies the issue as high severity with confidentiality impact, and the record indicates no privileges or user interaction are required.