← All CVEs

CVE-2025-5243

critical · 10

Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SMG Software Information Portal allows Code Injection, Upload a Web Shell to a Web Server, Code Inclusion. This issue affects Information Portal: before 13.06.2025.

10
CVSS
1.5%
EPSS (exploit prob.)
74th
EPSS percentile
2025-07-24
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-78CWE-434

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-5243