CVE-2025-32461

wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The fixed versions are 21.12, 24.8, 27.2, and 28.3.
Configurations

No configuration.

History

09 Apr 2025, 20:02

Type Values Removed Values Added
Summary
  • (es) En Tiki, el wikiplugin_includetpl en lib/wiki-plugins/wikiplugin_includetpl.php antes de la versión 28.3 gestiona incorrectamente la entrada a una evaluación. Las versiones corregidas son 21.12, 24.8, 27.2 y 28.3.

09 Apr 2025, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-09 02:15

Updated : 2025-04-09 20:02


NVD link : CVE-2025-32461

Mitre link : CVE-2025-32461

CVE.ORG link : CVE-2025-32461


JSON object : View

Products Affected

No product.

CWE
CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine