CVE-2025-24936

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
21/07/2025
Last modified:
23/07/2025

Description

The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound to the network stack and the set of possible attackers extends up to and including the entire Internet.<br /> <br /> An attacker with low privileged access to the application has the potential to execute commands on the operating system under the context of the webserver.