Executive brief
A vulnerability in Tiki Wiki CMS, a collaborative website management system, allows unauthorized individuals to access sensitive files on the server. By providing a specially crafted web address in the banner management section, an attacker can read internal system files. This could lead to the exposure of configuration data, passwords, or other private information stored on the hosting server.
Technical details
An arbitrary file read vulnerability exists in Tiki Wiki CMS 15.2 due to improper validation of the 'Use Image from URL' option within the banner management component. A remote, unauthenticated attacker can exploit this by submitting a crafted pathname in the banner URL field, which the application then processes without sufficient sanitization. This allows the attacker to bypass intended access restrictions and retrieve the contents of arbitrary files on the server's filesystem. The issue was addressed in subsequent revisions (e.g., SVN revision 60308) which improved how banner images from URLs are handled.
Affected products
- Tiki Tiki Wiki CMS Groupware 15.2
Timeline
- 2016-11-17: patched: Fix committed to SVN repository (r60308)
- 2017-01-20: disclosed: NVD publication date