First published: Sat Jan 14 2023(Updated: )
Tiki before 24.1, when the Spreadsheets feature is enabled, allows lib/sheet/grid.php PHP Object Injection because of an unserialize call.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tiki Tiki | <24.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22850 is considered a high-severity vulnerability due to its potential for PHP Object Injection.
To mitigate CVE-2023-22850, it is recommended to upgrade Tiki to version 24.1 or later where the vulnerability has been addressed.
CVE-2023-22850 affects Tiki versions prior to 24.1 when the Spreadsheets feature is enabled.
CVE-2023-22850 is a PHP Object Injection vulnerability caused by an insecure unserialize call in the Tiki application.
The Spreadsheets feature in Tiki is not safe to use in versions prior to 24.1 due to the existence of CVE-2023-22850.