Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-34111


An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's default connector (connector.minimal.php), which allows remote attackers to upload and execute malicious PHP scripts in the context of the web server. The vulnerable component does not enforce file type validation, allowing attackers to craft a POST request to upload executable PHP payloads through the ELFinder interface exposed at /vendor_extra/elfinder/.


Published

2025-07-15T13:15:30.980

Last Modified

2025-10-03T00:42:13.970

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-20
    CWE-306
    CWE-434
  • Type: Primary
    CWE-434

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application tiki tikiwiki_cms\/groupware ≤ 15.1 Yes

References