We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-5309

Remote Support & Privileged Remote Access server side template injection



Description

The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution.

Reserved 2025-05-28 | Published 2025-06-16 | Updated 2025-06-19 | Assigner BT


HIGH: 8.6CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-94 Improper Control of Generation of Code ('Code Injection')

Product status

Default status
unaffected

24.2.2
affected

24.3.1
affected

25.1.1
affected

Default status
unaffected

24.2.2
affected

24.3.1
affected

25.1.1
affected

Credits

Jorren Geurts of Resillion finder

References

www.beyondtrust.com/trust-center/security-advisories/bt25-04

cve.org (CVE-2025-5309)

nvd.nist.gov (CVE-2025-5309)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-5309

Support options

Helpdesk Chat, Email, Knowledgebase