CVE-2025-30091
In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command. This vulnerability allows unauthenticated attackers to inject and execute arbitrary code. Attacker-controlled data to InstallCommand can be inserted into config.php, and InstallCommand is available after an installation has completed.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.4
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 0.77%
- CWE
- CWE-96
- Published
- 2025-03-25
- Last modified
- 2026-03-12
Affected products
- Tiny MoxieManager PHP
Weakness type
Related vulnerabilities
- CVE-2026-86218 — pre-authentication remote code execution
- CVE-2025-57707 — File Station 5
- CVE-2025-7825 — Schema Plugin For Divi, Gutenberg & Shortcodes <= 4.3.2 - Authenticated (Contributor+) Object Instantiation
- CVE-2025-36595 — Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of...
- CVE-2015-2079 — Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution...
- CVE-2024-13268 — Opigno - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-032
- CVE-2024-13267 — Opigno TinCan Question Type - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-031
- CVE-2024-13265 — Opigno Learning path - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-029