Vulnerability Details CVE-2023-22853
Tiki before 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 72.2%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2023-22853
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:tiki:tiki:18.10
-
cpe:2.3:a:tiki:tiki:18.11
-
cpe:2.3:a:tiki:tiki:18.12
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:tiki:tiki:21.10
-
cpe:2.3:a:tiki:tiki:21.11
-
cpe:2.3:a:tiki:tiki:21.12
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-