PT-2026-46199 · Unknown · Pdf Signer

CVE-2019-25729

·

Published

2026-06-04

·

Updated

2026-06-04

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PDF Signer version 3.0
Description Server-side template injection allows unauthenticated attackers to execute arbitrary code by injecting PHP commands. This is achieved by crafting malicious values for the CSRF-TOKEN cookie parameter, utilizing template injection payloads such as the shell exec() function to execute system commands and retrieve sensitive information from the server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-25729

Affected Products

Pdf Signer