CVE-2019-25029
Executive Summary
Versa Director suffers from a command injection vulnerability (CVE‑2019‑25029) that allows attackers to execute arbitrary OS commands with the privileges of the vulnerable application. The flaw arises from insufficient input validation of user‑supplied data (e.g., form fields, cookies, HTTP headers) that is passed directly to a system shell. Exploitation can lead to full system compromise. No KEV listing yet.
Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2021-05-26T19:15:08.773 - Last Modified: 2026-08-31T18:08:14.137
Original Description: In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are possible when an application passes unsafe user supplied data (forms, cookies, HTTP headers etc.) to a system shell. In this attack, the attacker-supplied operating system commands are usually executed with the privileges of the vulnerable application. Command injection attacks are possible largely due to insufficient input validation.
"The conditions of conquest are always easy. We have but to toil awhile, endure awhile, believe always, and never turn back."
— Seneca