CVE-2024-47919: Tiki Wiki CMS – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Published Dec 30, 2024
·Updated
Tiki Wiki CMS – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Affected Software
1 affected component
Tiki Tiki Wiki CMS
Remediation
Information
Upgrade to version 28 or later
Event History
Dec 30, 2024
CVE Published
via MITRE·09:43 AM
Data Sourced
via MITRE·09:43 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-47919?
CVE-2024-47919 is classified as a medium severity vulnerability.
2
How does CVE-2024-47919 impact Tiki Wiki CMS?
CVE-2024-47919 allows for OS command injection due to improper neutralization of special elements.
3
How do I fix CVE-2024-47919 in Tiki Wiki CMS?
To fix CVE-2024-47919, update Tiki Wiki CMS to the latest version where this vulnerability is patched.
4
Who is affected by CVE-2024-47919?
Any installation of Tiki Wiki CMS that has not applied updates addressing this vulnerability is at risk.
5
What should I do if I cannot update Tiki Wiki CMS to mitigate CVE-2024-47919?
If an update is not feasible, avoid any functionality that allows OS command execution until a fix can be applied.