CVE-2025-57516: Command Injection
OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to execute arbitrary commands via crafted DATABASE, USERNAME, or PASSWORD variables to the backupDB.bat file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57516?
The severity of CVE-2025-57516 is classified as critical due to the potential for arbitrary command execution.
How do I fix CVE-2025-57516?
To fix CVE-2025-57516, update your PublicCMS to a version beyond V5.202506.b or apply any security patches provided by the vendor.
What types of systems are affected by CVE-2025-57516?
CVE-2025-57516 affects PublicCMS versions V5.202506.a and V5.202506.b.
What are the attack vectors for CVE-2025-57516?
CVE-2025-57516 can be exploited by attackers through crafted DATABASE, USERNAME, or PASSWORD variables in the backupDB.bat file.
Is CVE-2025-57516 exploitable remotely?
Yes, CVE-2025-57516 is exploitable remotely if proper network protections are not in place.