RULE(RULE ID:330969)

Rule General Information
Release Date: 2020-08-26
Rule Name: Typecho Deserialization Vulnerability (CVE-2023-24114)
Severity:
CVE ID:
Rule Protection Details
Description: Typecho is a PHP blogging platform for individual developers of typecho. Typecho 1.1/17.10.30 has a security vulnerability due to a deserialization vulnerability in install.php that allows arbitrary code execution.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux
Reference: https://github.com/typecho/typecho/issues/1523
https://cxsecurity.com/cveshow/CVE-2023-24114/
https://nvd.nist.gov/vuln/detail/CVE-2023-24114
Solutions
Refer to the announcement or patch by the vendor: https://github.com/typecho/typecho/issues/1523