{"id":"CVE-2017-9305","details":"lib/core/TikiFilter/PreventXss.php in Tiki Wiki CMS Groupware 16.2 allows remote attackers to bypass the XSS filter via padded zero characters, as demonstrated by an attack on tiki-batch_send_newsletter.php.","modified":"2026-07-08T16:54:56.868232Z","published":"2017-05-31T04:29:00.303Z","references":[{"type":"FIX","url":"https://github.com/tikiorg/tiki/commit/6c016e8f066d2f404b18eaa1af7fa0c7a9651ccd"},{"type":"EVIDENCE","url":"https://www.cdxy.me/?p=763"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tikiorg/tiki","events":[{"introduced":"d027438011aacbe400083c31d44b4b5519043113"},{"last_affected":"d027438011aacbe400083c31d44b4b5519043113"},{"fixed":"6c016e8f066d2f404b18eaa1af7fa0c7a9651ccd"}],"database_specific":{"cpe":"cpe:2.3:a:tiki:tikiwiki_cms\\/groupware:16.2:*:*:*:*:*:*:*","extracted_events":[{"introduced":"16.2"},{"last_affected":"16.2"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["16.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-9305.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}