Back

CVE-2014-7236

CRITICAL

Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenableplugins parameter to do/view/Main/WebHome.

Published: Feb 17, 2020 Modified: Jun 17, 2026
CWE-74

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products (7)

Vendor Product Version
twiki twiki * ≥ 4.0
twiki twiki * ≥ 4.1
twiki twiki * ≥ 4.2
twiki twiki * ≥ 4.3
twiki twiki * ≥ 5.0
twiki twiki * ≥ 5.1.0
twiki twiki 6.0

GitHub Security Advisory GHSA-8hcq-vp7p-r5fc

Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote...

References (8)

Risk Scores

CVSS Score 9.1 / 10
EPSS Score 55.64%

Top 1% most likely to be exploited

Threat Score 53.1 / 100

Data Sources

NVD EPSS GitHub