CVE-2025-30091

In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command. This vulnerability allows unauthenticated attackers to inject and execute arbitrary code. Attacker-controlled data to InstallCommand can be inserted into config.php, and InstallCommand is available after an installation has completed.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2025-03-25 14:15

Updated : 2025-03-27 16:45


NVD link : CVE-2025-30091

Mitre link : CVE-2025-30091

CVE.ORG link : CVE-2025-30091


JSON object : View

Products Affected

No product.

CWE
CWE-96

Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')