CVE-2023-22850: High severity tiki wiki cms groupware vulnerability
Published Jan 14, 2023
·Updated
Tiki before 24.1, when the Spreadsheets feature is enabled, allows lib/sheet/grid.php PHP Object Injection because of an unserialize call.
Affected Software
1 affected component
Tiki tiki<24.1
Event History
Jan 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-22850?
CVE-2023-22850 is considered a high-severity vulnerability due to its potential for PHP Object Injection.
2
How do I fix CVE-2023-22850?
To mitigate CVE-2023-22850, it is recommended to upgrade Tiki to version 24.1 or later where the vulnerability has been addressed.
3
What versions are affected by CVE-2023-22850?
CVE-2023-22850 affects Tiki versions prior to 24.1 when the Spreadsheets feature is enabled.
4
What type of vulnerability is CVE-2023-22850?
CVE-2023-22850 is a PHP Object Injection vulnerability caused by an insecure unserialize call in the Tiki application.
5
Is the Spreadsheets feature in Tiki safe to use with CVE-2023-22850?
The Spreadsheets feature in Tiki is not safe to use in versions prior to 24.1 due to the existence of CVE-2023-22850.