Junglewise Threat Intelligence

CVE-2019-25729: Simcy Creative PDF Signer SSTI in CSRF-TOKEN cookie

CVE-2019-25729 · Severity: critical · CVSS 9.8 · Published 2026-06-04

Executive brief

PDF Signer is a web application used to create digital signatures and sign PDF documents online. A critical vulnerability allows unauthenticated attackers to take complete control of the server by sending a specially crafted web request. This could lead to the theft of sensitive documents, exposure of customer data, or a total service outage.

Technical details

A Server-Side Template Injection (SSTI) vulnerability exists in PDF Signer 3.0 due to improper handling of the CSRF-TOKEN cookie and flawed CSRF implementation. An unauthenticated remote attacker can exploit this by injecting PHP commands (e.g., using shell_exec()) within the cookie value. The application reflects the cookie content into a template without proper sanitization, leading to Remote Code Execution (RCE). This allows for full system command execution and retrieval of sensitive server files like .env. No patch is currently documented in the advisory, though the software is listed on CodeCanyon.

Affected products

  • Simcy Creative PDF Signer 3.0

Timeline

  • 2019-01-28: disclosed: Initial discovery and exploit development by dd_ (Malicious Group)
  • 2019-01-29: other: Exploit published on Exploit-DB
  • 2026-06-04: advisory: CVE-2019-25729 published and added to NVD dataset

References