CVE-2023-22853: Code Injection
Published Jan 14, 2023
·Updated
Tiki before 24.1, when featurecreatewebhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval.
Affected Software
1 affected component
Tiki tiki<24.1
Event History
Jan 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-22853?
The severity of CVE-2023-22853 is classified as high due to the potential for PHP Object Injection.
2
How do I fix CVE-2023-22853?
To fix CVE-2023-22853, upgrade Tiki to version 24.1 or later and disable the feature_create_webhelp if it's not needed.
3
What kind of attack can exploit CVE-2023-22853?
CVE-2023-22853 can be exploited through PHP Object Injection attacks, allowing attackers to execute arbitrary code.
4
In which version of Tiki is CVE-2023-22853 present?
CVE-2023-22853 is present in Tiki versions prior to 24.1.
5
Is feature_create_webhelp safe in Tiki versions before 24.1?
No, enabling feature_create_webhelp in Tiki versions before 24.1 is not safe due to the vulnerability in CVE-2023-22853.