PT-2026-46199 · Simcy Creative · Pdf Signer

Published

2026-06-04

·

Updated

2026-06-04

·

CVE-2019-25729

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP commands through the CSRF-TOKEN cookie parameter. Attackers can craft malicious cookie values containing template injection payloads like shell exec() to execute system commands and retrieve sensitive information from the server.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2019-25729

Affected Products

Pdf Signer