Description
Unauthenticated users can download arbitrary files from the web server due to a vulnerability in vendor/player/flv/flv_stream.php.
Remediation
Upgrade Tiki Wiki CMS to version 12.8, 14.3, 15.1 or above (recommended)
References
Related Vulnerabilities
Apache httpOnly cookie disclosure
WordPress Plugin NextGEN Gallery-WordPress Gallery Information Disclosure (1.9.11)
WordPress Plugin U Extended Comment 'fileurl' Parameter Arbitrary File Download (1.0.1)
vBulletin customer number disclosure
WordPress Plugin Wholesale Market for WooCommerce Arbitrary File Download (1.0.6)