PT-2026-41373 · Orsee · Orsee

Published

2026-05-15

·

Updated

2026-05-18

·

CVE-2025-67031

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions ORSEE (Online Recruitment System for Economic Experiments) version 3.1.0
Description An authenticated Remote Code Execution issue exists in the participant profile field processing subsystem. Certain field configurations allow values starting with the prefix "func:" to be passed directly into an eval() function (a function that executes a string as code) within the files 'tagsets/participant.php' and 'tagsets/options.php'.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-67031

Affected Products

Orsee