Description
Cross-site scripting (XSS) vulnerability in tiki-view_forum_thread.php in TikiWiki 1.9.0 through 1.9.2 allows remote attackers to inject arbitrary web script or HTML via the topics_offset parameter.
Affected products
- Tiki / tikiwiki_cms/groupware1.9.0 – 1.9.0
- Tiki / tikiwiki_cms/groupware1.9.1 – 1.9.1
- Tiki / tikiwiki_cms/groupware1.9.2 – 1.9.2