9.8
CVSSv3

CVE-2020-15906

Published: 22/10/2020 Updated: 03/11/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

tiki-login.php in Tiki prior to 21.2 sets the admin password to a blank value after 50 invalid login attempts.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tiki tiki

Exploits

Tiki Wiki CMS Groupware version 211 suffers from an authentication bypass vulnerability ...

Github Repositories

Writeup of CVE-2020-15906

CVE-2020-15906 Writeup of CVE-2020-15906 Special Thanks to Frederic Mohr(Lastbreach) for your Backend Support Tiki Wiki Cms Groupware 16x - 211 Authentication Bypass by Maximilian Barz I have found a new vulnerability in TikiWiki Cms Groupware 16x - 211 It allows remote unauthenticated attackers to bypass the login page which results in a full compromise of Tiki Wiki CM