← volver
CVE-2025-34104criticalCWE-306CWE-434

Piwik Authenticated RCE via Custom Plugin Upload

43Vexday Risk Score

Corrige pronto. Ella tiene exploit funcional público.

ssvc Attendcvss 9.4epss 1.1%
de la publicación al arma0 días
Publicada en NVD15 jul
metasploit5 feb
probabilidad de explotación
1.1%top 36% de las CVE
explotación observada
noninguna fuente lo reporta
An authenticated remote code execution vulnerability exists in Piwik (now Matomo) versions prior to 3.0.3 via the plugin upload mechanism. In vulnerable versions, an authenticated user with Superuser privileges can upload and activate a malicious plugin (ZIP archive), leading to arbitrary PHP code execution on the underlying system. Starting with version 3.0.3, plugin upload functionality is disabled by default unless explicitly enabled in the configuration file.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H