Home
HIGH: 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
24.2.2 (custom)
affected
24.3.1 (custom)
affected
25.1.1 (custom)
affected
Default status
unaffected
24.2.2 (custom)
affected
24.3.1 (custom)
affected
25.1.1 (custom)
affected
Description
The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution.
Problem types
CWE-94 Improper Control of Generation of Code ('Code Injection')
Product status
24.2.2 (custom)
24.3.1 (custom)
25.1.1 (custom)
24.2.2 (custom)
24.3.1 (custom)
25.1.1 (custom)
Credits
Jorren Geurts of Resillion
References
www.beyondtrust.com/trust-center/security-advisories/bt25-04
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.