PHP Object Injection Vulnerability in Tiki Wiki before 24.1
CVE-2023-22853
8.8HIGH
What is CVE-2023-22853?
A vulnerability exists in Tiki Wiki versions prior to 24.1, where enabling the feature_create_webhelp can lead to PHP Object Injection due to the unsafe use of eval in lib/structures/structlib.php. This flaw allows attackers to execute arbitrary code, potentially compromising the integrity and security of the application.