Security
Headlines
HeadlinesLatestCVEs

Headline

Tiki Wiki CMS Groupware 25.0 Cross Site Request Forgery

Tiki Wiki CMS Groupware versions 25.0 and below suffer from multiple cross site request forgery vulnerabilities.

Packet Storm
#csrf#vulnerability#web#php#auth

Tiki Wiki CMS Groupware <= 25.0 Two Cross-Site Request Forgery
Vulnerabilities


[-] Software Link:

https://tiki.org

[-] Affected Versions:

Version 25.0 and prior versions.

[-] Vulnerabilities Description:

  1. The /tiki-importer.php script does not implement any protection
    against Cross-Site Request Forgery (CSRF) attacks. As such, an attacker
    might force an authenticated user to import arbitrary content (wiki
    pages) into TikiWiki by tricking a victim user into browsing to a
    specially crafted web page.

  2. The /tiki-import_sheet.php script does not implement any protection
    against Cross-Site Request Forgery (CSRF) attacks. As such, an attacker
    might force an authenticated user to import arbitrary sheets into
    TikiWiki by tricking a victim user into browsing to a specially crafted
    web page. Successful exploitation of this vulnerability requires the
    “Spreadsheets” feature to be enabled.

[-] Solution:

No official solution is currently available.

[-] Disclosure Timeline:

[06/03/2022] - Vendor notified
[09/01/2023] - Public disclosure

[-] CVE Reference:

The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CVE-2023-22852 to this vulnerability.

[-] Credits:

Vulnerabilities discovered by Egidio Romano.

[-] Original Advisory:

http://karmainsecurity.com/KIS-2023-01

Related news

CVE-2023-22852: Tiki Wiki CMS Groupware <= 25.0 Two Cross-Site Request Forgery Vulnerabilities

Tiki through 25.0 allows CSRF attacks that are related to tiki-importer.php and tiki-import_sheet.php.

Packet Storm: Latest News

Acronis Cyber Protect/Backup Remote Code Execution