Description
The image upload feature in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to upload and possibly execute arbitrary files via the img/wiki_up URL.
Affected products
- Tiki / tikiwiki_cms/groupware1.8.1
- Tiki / tikiwiki_cms/groupware1.6.1 – 1.6.1