Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-22852: Tiki Wiki CMS Groupware <= 25.0 Two Cross-Site Request Forgery Vulnerabilities

Tiki through 25.0 allows CSRF attacks that are related to tiki-importer.php and tiki-import_sheet.php.

CVE
#csrf#vulnerability#web#php#auth

Tiki Wiki CMS Groupware <= 25.0 Two Cross-Site Request Forgery Vulnerabilities

• Software Link:

https://tiki.org

• Affected Versions:

Version 25.0 and prior versions.

• Vulnerabilities Description:

  1. The /tiki-importer.php script does not implement any protection against Cross-Site Request Forgery (CSRF) attacks. As such, an attacker might force an authenticated user to import arbitrary content (wiki pages) into TikiWiki by tricking a victim user into browsing to a specially crafted web page.

  2. The /tiki-import_sheet.php script does not implement any protection against Cross-Site Request Forgery (CSRF) attacks. As such, an attacker might force an authenticated user to import arbitrary sheets into TikiWiki by tricking a victim user into browsing to a specially crafted web page. Successful exploitation of this vulnerability requires the “Spreadsheets” feature to be enabled.

• Solution:

No official solution is currently available.

• Disclosure Timeline:

[06/03/2022] – Vendor notified
[09/01/2023] – Public disclosure

• CVE Reference:

The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CVE-2023-22852 to this vulnerability.

• Credits:

Vulnerabilities discovered by Egidio Romano.

Related news

Tiki Wiki CMS Groupware 25.0 Cross Site Request Forgery

Tiki Wiki CMS Groupware versions 25.0 and below suffer from multiple cross site request forgery vulnerabilities.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907