Description
The RunCommand function accepts any parameter, which is then passed for execution in the shell. This allows an attacker to execute arbitrary code on the system.
Problem types
CWE-94 Improper Control of Generation of Code ('Code Injection')
Product status
Any version before 2024.MS4.33
Credits
Maciej Kazulak
References
cert.pl/en/posts/2025/08/CVE-2025-2313/