Executive brief
Use It Flow is an administration and workflow management platform. A security flaw in its administration interface allows an attacker to execute unauthorized commands on the server. This could lead to a complete system takeover, theft of sensitive business data, or the installation of malicious software. Organizations using versions prior to 10.0.0 are at risk of total operational compromise.
Technical details
A Remote Code Execution (RCE) vulnerability exists in 'flow/admin/moniteur.php' due to the unsafe use of the PHP eval() function. The script accepts user input via the 'action' GET parameter and attempts to validate it using method_exists(). However, the validation only checks the string prefix before the first parenthesis, allowing an attacker to append arbitrary PHP statements after a valid method call (e.g., 'valid_method(); phpinfo();'). The input is then concatenated into a string and executed. While the CVSS vector suggests low privileges are required, the vulnerability may be reachable with trivial or no authentication depending on the specific environment configuration. The issue is resolved in version 10.0.0.
Affected products
- Tenor Solutions (formerly API SAS) Use It Flow before 10.0.0
Timeline
- 2025-04-22: other: Vendor notified of vulnerabilities
- 2025-04-24: other: Vendor confirmed vulnerability in versions 8 and 9
- 2026-03-16: disclosed: Full disclosure of vulnerability details
- 2026-03-16: advisory: CVE published to NVD