Vulnerabilities
CVE-2019-25243 - FaceSentry 6.4.8 Authenticated Remote Command Injection via Ping Test
CVE ID : CVE-2019-25243 Published : Dec. 24, 2025, 8:15 p.m. | 1 hour, 30 minutes ago Description : FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary shell commands with root privileges by manipulating the 'strInIP' and 'strInPort' parameters. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE Details
Affected Product:
php
Impact:
command injection
Source: Telegram CVE Monitor