An issue in PocketVJ CP PocketVJ-CP-v3 pvj 3.9.1 allows remote attackers to execute arbitrary code via the submit_size.php component.
References
| Link | Resource |
|---|---|
| https://gist.github.com/mamdouhalrekabi-ops/3e230eb973101aa6ac7003427a723e29 | Third Party Advisory |
| https://github.com/magdesign/PocketVJ-CP-v3/releases/tag/release | Release Notes |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2025-09-23 19:15
Updated : 2025-10-17 15:11
NVD link : CVE-2025-45326
Mitre link : CVE-2025-45326
CVE.ORG link : CVE-2025-45326
JSON object : View
Products Affected
magdesign
- pocketvj_control_panel
- pocketvj_control_panel_firmware
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
