CVE-2020-15906 describes a critical authentication bypass vulnerability in Tiki Wiki CMS GroupWare versions prior to 21.2. An attacker can exploit a flaw in tiki-login.php where 50 invalid login attempts reset the administrator password to a blank value. This allows for complete compromise of the affected system, as reflected by its CVSS score of 9.8 (Critical) and FAUCET Risk Score of 100/100. While not listed on CISA's KEV catalog, exploit intelligence indicates the availability of Nuclei templates for this vulnerability, and it has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 16.3, < 21.2CPE matchmatch criteria | cpe:2.3:a:tiki:tiki:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.