CVE-2019-25729
CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP commands through the CSRF-TOKEN cookie parameter. Attackers can craft malicious cookie values containing template injection payloads like shell_exec() to execute system commands and retrieve sensitive information from the server.
Metadata
Severity & Metrics
9.8
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| simcy_creative | PDF Signer | — | 3.0 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-352 | cna | Cross-Site Request Forgery (CSRF) |
CVSS scores (2)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 9.8 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 9.3 | CRITICAL | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
References (4)
- ExploitDB-46276 https://www.exploit-db.com/exploits/46276
- Official Product Homepage https://codecanyon.net/user/simcy_creative
- Product Reference https://codecanyon.net/item/signer-create-digital-signatures-and-sign-pdf-documents-online/20737707
- VulnCheck Advisory: PDF Signer 3.0 Server-Side Template Injection RCE via CSRF Cookie https://www.vulncheck.com/advisories/pdf-signer-server-side-template-injection-rce-via-csrf-cookie