PT-2026-43390 · Git · Public-References
CVE-2025-50329
·
Published
2026-05-26
·
Updated
2026-07-23
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ConeXware, Inc Power Archiver versions prior to 22.00.12
Drupal (affected versions not specified)
Description
An issue in the
powerarc.exe executable allows a remote attacker to escalate privileges and execute arbitrary code. Separately, a SQL injection exists in Drupal that allows for database compromise without requiring authentication. SQL injection is a technique where an attacker inserts malicious SQL code into a query, allowing them to manipulate the database.Recommendations
Update ConeXware, Inc Power Archiver to version 22.00.12 or later.
Apply the latest security patches to Drupal to resolve the SQL injection issue.
Exploit
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Public-References