CVE-2020-16131

Tiki before 21.2 allows XSS because [\s\/"\'] is not properly considered in lib/core/TikiFilter/PreventXss.php.

Score

4.3

Source

http://nvd.nist.gov

Access-complexity

MEDIUM

Access-vector

NETWORK