CVE-2025-30057
Severity CVSS v4.0:
CRITICAL
Type:
CWE-94
Code Injection
Publication date:
27/08/2025
Last modified:
29/08/2025
Description
In UHCRTFDoc, the filename parameter can be exploited to execute arbitrary code via command injection into the system() call in the ConvertToPDF function.
Impact
Base Score 4.0
9.40
Severity 4.0
CRITICAL



