-
Notifications
You must be signed in to change notification settings - Fork 209
Open
Labels
Contributor mainThe main issue a contributor is working on (top of the contribution queue).The main issue a contributor is working on (top of the contribution queue).PRP:Accepted
Description
- Identifier of the vulnerability: CVE-2025-34111
- Affected software: Tiki Wiki CMS Groupware
- Type of vulnerability: Unauthenticated file upload leads to RCE
- Requires authentication: No
- Language you would use for writing the plugin: Templated plugins
- Resources:
https://nvd.nist.gov/vuln/detail/CVE-2025-34111
https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/tikiwiki_upload_exec.rb
https://tiki.org/article434-Security-update-Tiki-15-2-Tiki-14-4-and-Tiki-12-9-released
https://www.exploit-db.com/exploits/40091
https://www.vulncheck.com/advisories/tiki-wiki-el-finder-unauthenticated-file-upload-rce
Metadata
Metadata
Assignees
Labels
Contributor mainThe main issue a contributor is working on (top of the contribution queue).The main issue a contributor is working on (top of the contribution queue).PRP:Accepted