Tiki before 24.1, when the Spreadsheets feature is enabled, allows lib/sheet/grid.php PHP Object Injection because of an unserialize call.Referenceshttps://tiki.org/articleshttps://karmainsecurity.com/KIS-2023-03