wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The fixed versions are 21.12, 24.8, 27.2, and 28.3.
References
Configurations
No configuration.
History
09 Apr 2025, 20:02
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
09 Apr 2025, 02:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-09 02:15
Updated : 2025-04-09 20:02
NVD link : CVE-2025-32461
Mitre link : CVE-2025-32461
CVE.ORG link : CVE-2025-32461
JSON object : View
Products Affected
No product.
CWE
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine