← Back to CVE List

CVE-2025-30091

Published: 2025-03-25T14:15Z
Last Modified: 2025-03-25T14:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command. This vulnerability allows unauthenticated attackers to inject and execute arbitrary code. Attacker-controlled data to InstallCommand can be inserted into config.php, and InstallCommand is available after an installation has completed. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt