CVE-2025-13284: ThinPLUS|ThinPLUS - OS Command Injection
ThinPLUS developed by ThinPLUS has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13284?
CVE-2025-13284 is considered a critical vulnerability due to its ability to allow unauthenticated remote command execution on the server.
How do I fix CVE-2025-13284?
To fix CVE-2025-13284, update the ThinPLUS software to the latest version that addresses the OS Command Injection vulnerability.
Who is affected by CVE-2025-13284?
Organizations using ThinPLUS software are affected by CVE-2025-13284, particularly if they have not applied recent security updates.
What kind of attacks can be executed using CVE-2025-13284?
CVE-2025-13284 allows attackers to inject arbitrary OS commands, leading to potential system compromise or data breaches.
Is authentication required to exploit CVE-2025-13284?
No, CVE-2025-13284 can be exploited by unauthenticated attackers, making it particularly dangerous.