Executive brief
SMG Software Information Portal contains a critical security flaw that allows unauthorized individuals to upload malicious files and execute commands on the server. This portal is typically used for managing and sharing organizational information; an exploit could lead to a complete takeover of the system, theft of sensitive data, or a total service outage. Organizations using versions released before June 13, 2025, are at high risk and should update immediately.
Technical details
The SMG Software Information Portal is vulnerable to both Unrestricted File Upload (CWE-434) and OS Command Injection (CWE-78). The vulnerability stems from improper validation of uploaded file types and a failure to neutralize special elements used in operating system commands. An unauthenticated remote attacker can exploit these flaws to upload a web shell or inject malicious code, leading to full remote code execution (RCE) with the privileges of the web server. The issue is resolved in versions released on or after June 13, 2025. The CVSS score of 10.0 reflects the lack of required authentication and the high impact on confidentiality, integrity, and availability.
Affected products
- SMG Software Information Portal before 13.06.2025
Timeline
- 2025-07-24: advisory: Initial publication of CVE-2025-5243
- 2025-06-13: patched: Fix released in version 13.06.2025