Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mpf8-7ggf-mqcv

Опубликовано: 15 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

An authenticated command injection vulnerability exists in Tiki Wiki CMS versions ≤14.1, ≤12.4 LTS, ≤9.10 LTS, and ≤6.14 via the viewmode GET parameter in tiki-calendar.php. When the calendar module is enabled and an authenticated user has permission to access it, an attacker can inject and execute arbitrary PHP code. Successful exploitation leads to remote code execution in the context of the web server user.

An authenticated command injection vulnerability exists in Tiki Wiki CMS versions ≤14.1, ≤12.4 LTS, ≤9.10 LTS, and ≤6.14 via the viewmode GET parameter in tiki-calendar.php. When the calendar module is enabled and an authenticated user has permission to access it, an attacker can inject and execute arbitrary PHP code. Successful exploitation leads to remote code execution in the context of the web server user.

EPSS

Процентиль: 97%
0.40157
Средний

8.7 High

CVSS4

Дефекты

CWE-20

Связанные уязвимости

nvd
7 месяцев назад

An authenticated command injection vulnerability exists in Tiki Wiki CMS versions ≤14.1, ≤12.4 LTS, ≤9.10 LTS, and ≤6.14 via the `viewmode` GET parameter in `tiki-calendar.php`. When the calendar module is enabled and an authenticated user has permission to access it, an attacker can inject and execute arbitrary PHP code. Successful exploitation leads to remote code execution in the context of the web server user.

debian
7 месяцев назад

An authenticated command injection vulnerability exists in Tiki Wiki C ...

EPSS

Процентиль: 97%
0.40157
Средний

8.7 High

CVSS4

Дефекты

CWE-20