An issue in PocketVJ CP PocketVJ-CP-v3 pvj 3.9.1 allows remote attackers to execute arbitrary code via the submit_size.php component.
References
Link | Resource |
---|---|
https://gist.github.com/mamdouhalrekabi-ops/3e230eb973101aa6ac7003427a723e29 | Third Party Advisory |
https://github.com/magdesign/PocketVJ-CP-v3/releases/tag/release | Release Notes |
Configurations
Configuration 1 (hide)
AND |
|
History
17 Oct 2025, 15:11
Type | Values Removed | Values Added |
---|---|---|
References | () https://gist.github.com/mamdouhalrekabi-ops/3e230eb973101aa6ac7003427a723e29 - Third Party Advisory | |
References | () https://github.com/magdesign/PocketVJ-CP-v3/releases/tag/release - Release Notes | |
First Time |
Magdesign pocketvj Control Panel
Magdesign Magdesign pocketvj Control Panel Firmware |
|
CPE | cpe:2.3:o:magdesign:pocketvj_control_panel_firmware:3.9.1:*:*:*:*:*:*:* cpe:2.3:h:magdesign:pocketvj_control_panel:-:*:*:*:*:*:*:* |
24 Sep 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-77 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
23 Sep 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-23 19:15
Updated : 2025-10-17 15:11
NVD link : CVE-2025-45326
Mitre link : CVE-2025-45326
CVE.ORG link : CVE-2025-45326
JSON object : View
Products Affected
magdesign
- pocketvj_control_panel
- pocketvj_control_panel_firmware
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')