PT-2025-29553 · Unknown+1 · Tikiwiki Cms/Groupware+1

Mehmet Ince

·

Published

2025-07-15

·

Updated

2025-07-15

·

CVE-2025-34111

CVSS v3.1

9.8

Critical

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tiki Wiki CMS Groupware versions 15.1 and earlier
Description An unauthenticated arbitrary file upload issue exists in the Tiki Wiki CMS Groupware software. The vulnerability is located within the ELFinder component’s default connector (connector.minimal.php). It allows remote attackers to upload and execute malicious PHP scripts in the context of the web server due to a lack of file type validation. Attackers can craft a POST request to upload executable PHP payloads through the ELFinder interface exposed at /vendor extra/elfinder/.
Recommendations Versions prior to 15.1 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Unrestricted File Upload

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-34111

Affected Products

Elfinder
Tikiwiki Cms/Groupware