Description
An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's default connector (connector.minimal.php), which allows remote attackers to upload and execute malicious PHP scripts in the context of the web server. The vulnerable component does not enforce file type validation, allowing attackers to craft a POST request to upload executable PHP payloads through the ELFinder interface exposed at /vendor_extra/elfinder/.
INFO
Published Date :
2025-07-15T13:09:56.350Z
Last Modified :
2026-04-07T14:09:37.876Z
Source :
VulnCheck
AFFECTED PRODUCTS
The following products are affected by CVE-2025-34111 vulnerability.
| Vendors | Products |
|---|---|
| Tiki |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-34111.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact