CVE Vulnerabilities

CVE-2010-1136

Published: Mar 27, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Standard Remember method in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to bypass access restrictions related to persistent login, probably due to the generation of predictable cookies based on the IP address and User agent in userslib.php.

Affected Software

NameVendorStart VersionEnd Version
Tikiwiki_cms/groupwareTiki3.0 (including)3.0 (including)
Tikiwiki_cms/groupwareTiki3.1 (including)3.1 (including)
Tikiwiki_cms/groupwareTiki3.2 (including)3.2 (including)
Tikiwiki_cms/groupwareTiki3.3 (including)3.3 (including)
Tikiwiki_cms/groupwareTiki3.4 (including)3.4 (including)

References