CVE-2025-65480

An issue was discovered in Pacom Unison Client 5.13.1. Authenticated users can inject malicious scripts in the Report Templates which are executed when certain script conditions are fulfilled, leading to Remote Code Execution.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en Pacom Unison Cliente 5.13.1. Los usuarios autenticados pueden inyectar scripts maliciosos en las Plantillas de Informes que se ejecutan cuando se cumplen ciertas condiciones de script, lo que lleva a Ejecución Remota de Código.

12 Feb 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-78

11 Feb 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-11 18:16

Updated : 2026-04-15 00:35


NVD link : CVE-2025-65480

Mitre link : CVE-2025-65480

CVE.ORG link : CVE-2025-65480


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')