cve/2025/CVE-2025-30091.md
2025-09-29 21:09:30 +02:00

908 B

CVE-2025-30091

Description

In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command. This vulnerability allows unauthenticated attackers to inject and execute arbitrary code. Attacker-controlled data to InstallCommand can be inserted into config.php, and InstallCommand is available after an installation has completed.

POC

Reference

No PoCs from references.

Github