CVE-2023-22851: Malicious File Upload
Published Jan 14, 2023
·Updated
Tiki before 24.2 allows lib/importer/tikiimporterblogwordpress.php PHP Object Injection by an admin because of an unserialize call.
Affected Software
1 affected component
Tiki tiki<24.2
Event History
Jan 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-22851?
CVE-2023-22851 has been classified as a high severity vulnerability due to its potential for PHP Object Injection.
2
How do I fix CVE-2023-22851?
To fix CVE-2023-22851, upgrade your Tiki installation to version 24.2 or later.
3
Who is affected by CVE-2023-22851?
CVE-2023-22851 affects all Tiki installations prior to version 24.2.
4
What type of vulnerability is CVE-2023-22851?
CVE-2023-22851 is a PHP Object Injection vulnerability that can be exploited by an admin user.
5
What component of Tiki is involved in CVE-2023-22851?
The vulnerability in CVE-2023-22851 is related to the lib/importer/tikiimporter_blog_wordpress.php file.