PT-2026-54746 · Unknown · Guardian Language-System
Philopentest
·
Published
2026-07-01
·
Updated
2026-07-01
·
CVE-2026-34110
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Guardian language-system (affected versions not specified)
Description
An unauthenticated remote attacker can execute arbitrary OS commands on the server. The issue occurs because the application passes the
id GET parameter directly into a PHP exec() function within the complex start.php file without proper sanitization. This allows the injection of shell metacharacters to trigger command execution.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Guardian Language-System