Vulnerability Description
ORSEE (Online Recruitment System for Economic Experiments) 3.1.0 contains an authenticated Remote Code Execution vulnerability in the participant profile field processing subsystem. Certain field configurations accept values beginning with the prefix "func:" which are passed directly into an eval() call inside tagsets/participant.php and tagsets/options.php.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/orsee/orsee/archive/refs/tags/orsee_3.1.0.zip
- https://medium.com/@erabhishekshroti/cve-2025-67031-remote-code-execution-in-ors
FAQ
What is CVE-2025-67031?
CVE-2025-67031 is a vulnerability with a CVSS score of 6.3 (MEDIUM). ORSEE (Online Recruitment System for Economic Experiments) 3.1.0 contains an authenticated Remote Code Execution vulnerability in the participant profile field processing subsystem. Certain field conf...
How severe is CVE-2025-67031?
CVE-2025-67031 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-67031?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.