PT-2025-29546 · Matomo · Matomo

Firefart

·

Published

2025-07-15

·

Updated

2025-07-15

·

CVE-2025-34104

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Matomo versions prior to 3.0.3
Description An authenticated remote code execution issue exists in Matomo due to the plugin upload mechanism. An authenticated user with Superuser privileges can upload and activate a malicious plugin (ZIP archive), resulting in arbitrary PHP code execution on the underlying system. From version 3.0.3, plugin upload functionality is disabled by default unless explicitly enabled in the configuration file.
Recommendations Update to version 3.0.3 or later. As a temporary workaround, disable the plugin upload functionality in the configuration file.

Exploit

Fix

Unrestricted File Upload

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-34104

Affected Products

Matomo