CVE-2011-4825: Phpletter AJAX File And Image Manager

High severity, CVSS 7.5. EPSS: 39.2% chance of exploitation in the next 30 days.

Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.

Affected products

  • Phpletter AJAX File And Image Manager: up to and including 1.0; version 0.5 only; version 0.5.5 only; version 0.5.7 only; version 0.6 only; version 0.6.12 only; …
  • Phpmyfaq Phpmyfaq: version 2.6.0 only; version 2.6.1 only; version 2.6.2 only; version 2.6.3 only; version 2.6.4 only; version 2.6.5 only; …
  • Tinymce Tinymce: up to and including 1.4.1

Published 2011-12-15. Last modified 2026-06-16.