PT-2024-32894 · Unknown · Tiki Wiki Cms
Published
2024-12-30
·
Updated
2025-01-06
·
CVE-2024-47919
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tiki Wiki CMS versions prior to 28
Description
The issue is related to improper neutralization of special elements used in an OS command, also known as 'OS Command Injection'. This occurs when the software does not properly handle special elements in OS commands, potentially allowing attackers to execute arbitrary commands.
Recommendations
For versions prior to 28, upgrade to version 28 as soon as possible to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the CMS to minimize the risk of exploitation.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tiki Wiki Cms