CVE-2025-30055

Severity CVSS v4.0:
CRITICAL
Type:
CWE-94 Code Injection
Publication date:
27/08/2025
Last modified:
29/08/2025

Description

The "system" function receives untrusted input from the user. If the "EnableJSCaching" option is enabled, it is possible to execute arbitrary code provided as the "Module" parameter.

References to Advisories, Solutions, and Tools