CVE-2025-5243

Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SMG Software Information Portal allows Code Injection, Upload a Web Shell to a Web Server, Code Inclusion. This issue affects Information Portal: before 13.06.2025.
Configurations

No configuration.

History

05 Jun 2026, 15:16

Type Values Removed Values Added
References
  • () https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0174 -
Summary (en) Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SMG Software Information Portal allows Code Injection, Upload a Web Shell to a Web Server, Code Inclusion.This issue affects Information Portal: before 13.06.2025. (en) Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SMG Software Information Portal allows Code Injection, Upload a Web Shell to a Web Server, Code Inclusion. This issue affects Information Portal: before 13.06.2025.

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad en SMG Software Information Portal que permite la inyección de código, la carga de un shell web a un servidor web y la inclusión de código, provoca la carga sin restricciones de archivos de tipo peligroso y la neutralización incorrecta de elementos especiales utilizados en un comando del sistema operativo ('Inyección de comando del sistema operativo'). Este problema afecta a Information Portal: antes del 13/06/2025.

24 Jul 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-24 13:15

Updated : 2026-06-17 09:47


NVD link : CVE-2025-5243

Mitre link : CVE-2025-5243

CVE.ORG link : CVE-2025-5243


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-434

Unrestricted Upload of File with Dangerous Type