Tiki before 24.2 allows lib/importer/tikiimporter_blog_wordpress.php PHP Object Injection by an admin because of an unserialize call.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://tiki.org/articles | vendor advisory |
https://karmainsecurity.com/KIS-2023-04 | third party advisory exploit |