CVE-2023-22852: CSRF
Published Jan 14, 2023
·Updated
Tiki through 25.0 allows CSRF attacks that are related to tiki-importer.php and tiki-importsheet.php.
Affected Software
1 affected component
Tiki tiki<=25.0
Event History
Jan 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-22852?
CVE-2023-22852 has a medium severity level due to its potential for CSRF attacks.
2
How do I fix CVE-2023-22852?
To fix CVE-2023-22852, update Tiki to version 25.1 or later, where the vulnerability is addressed.
3
What components are affected by CVE-2023-22852?
CVE-2023-22852 affects the tiki-importer.php and tiki-import_sheet.php components in Tiki through version 25.0.
4
What type of vulnerability is CVE-2023-22852?
CVE-2023-22852 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Can CVE-2023-22852 be exploited remotely?
Yes, CVE-2023-22852 can be exploited remotely, allowing attackers to compromise affected systems.