Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-34113

Опубликовано: 15 июл. 2025
Источник: nvd
EPSS Средний

Описание

An authenticated command injection vulnerability exists in Tiki Wiki CMS versions ≤14.1, ≤12.4 LTS, ≤9.10 LTS, and ≤6.14 via the viewmode GET parameter in tiki-calendar.php. When the calendar module is enabled and an authenticated user has permission to access it, an attacker can inject and execute arbitrary PHP code. Successful exploitation leads to remote code execution in the context of the web server user.

EPSS

Процентиль: 97%
0.40157
Средний

Дефекты

CWE-20

Связанные уязвимости

debian
7 месяцев назад

An authenticated command injection vulnerability exists in Tiki Wiki C ...

github
7 месяцев назад

An authenticated command injection vulnerability exists in Tiki Wiki CMS versions ≤14.1, ≤12.4 LTS, ≤9.10 LTS, and ≤6.14 via the `viewmode` GET parameter in `tiki-calendar.php`. When the calendar module is enabled and an authenticated user has permission to access it, an attacker can inject and execute arbitrary PHP code. Successful exploitation leads to remote code execution in the context of the web server user.

EPSS

Процентиль: 97%
0.40157
Средний

Дефекты

CWE-20