CVE-2012-3996: Tiki Tikiwiki Cms/groupware
Medium severity, CVSS 5.0. EPSS: 4.6% chance of exploitation in the next 30 days.
TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (1) admin/include_calendar.php, (2) tiki-rss_error.php, or (3) tiki-watershed_service.php.
Affected products
- Tiki Tikiwiki Cms/groupware: up to and including 8.2; version 2.2 only; version 3.0 only; version 3.1 only; version 3.2 only; version 3.3 only; …
Published 2012-07-12. Last modified 2026-06-16.