PT-2025-9252 · Unknown · Esafenet Dsm

207556249

·

Publicado

2025-03-02

·

Atualizado

2025-03-03

·

CVE-2025-1845

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ESAFENET DSM version 3.1.2
Description A critical issue has been discovered, affecting the examExportPDF function in the /admin/plan/examExportPDF file. The manipulation of the s argument leads to command injection. This issue can be exploited remotely.
Recommendations For ESAFENET DSM version 3.1.2, as a temporary workaround, consider disabling the examExportPDF function until a patch is available. Restrict access to the /admin/plan/examExportPDF file to minimize the risk of exploitation. Avoid using the s argument in the affected function until the issue is resolved.

Exploit

Correção

Special Elements Injection

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-04948
CVE-2025-1845

Produtos afetados

Esafenet Dsm