NA

CVE-2023-22853

Published: 14/01/2023 Updated: 23/01/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Tiki prior to 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tiki tiki

Exploits

Tiki Wiki CMS Groupware versions 240 and below suffer from a PHP code injection vulnerability in structlibphp ...