Description
The "system" function receives untrusted input from the user. If the "EnableJSCaching" option is enabled, it is possible to execute arbitrary code provided as the "Module" parameter.
Problem types
CWE-94 Improper Control of Generation of Code ('Code Injection')
Product status
Any version before 2024.MS4
Credits
Maciej Kazulak
References
cert.pl/en/posts/2025/08/CVE-2025-2313/