OS Command Injection Vulnerability in Tiki Wiki CMS
CVE-2024-47919

9.8CRITICAL

Key Information:

Vendor

Tiki Wiki

Status
Vendor
CVE Published:
30 December 2024

What is CVE-2024-47919?

An OS command injection vulnerability exists in Tiki Wiki CMS due to improper neutralization of special elements used in OS commands. This weakness allows malicious actors to manipulate system commands, potentially leading to unauthorized access, data breaches, or even complete system compromise. Attackers can exploit this vulnerability by injecting commands through user inputs, putting installations of Tiki Wiki CMS at significant risk. Regular updates and vulnerability assessments are essential to safeguard against such exploits.

Affected Version(s)

CMS All versions

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aviv Vinograzki - Peer Security LTD
.