Vulnerability Description
A Remote Code Execution (RCE) vulnerability was found in Smanga 3.2.7 in the /php/path/rescan.php interface. The application fails to properly sanitize user-supplied input in the mediaId parameter before using it in a system shell command. This allows an unauthenticated attacker to inject arbitrary operating system commands, leading to complete server compromise.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lkw199711 | Smanga | 3.2.7 |
Related Weaknesses (CWE)
References
- https://github.com/LX-66-LX/cve/issues/5Broken Link
FAQ
What is CVE-2025-70831?
CVE-2025-70831 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A Remote Code Execution (RCE) vulnerability was found in Smanga 3.2.7 in the /php/path/rescan.php interface. The application fails to properly sanitize user-supplied input in the mediaId parameter bef...
How severe is CVE-2025-70831?
CVE-2025-70831 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-70831?
Check the references section above for vendor advisories and patch information. Affected products include: Lkw199711 Smanga.