VDB

CVE-2025-34030

CVE-2025-34030 PUBLISHED CVSS 10 CRITICAL

An OS command injection vulnerability exists in sar2html version 3.2.2 and prior via the plot parameter in index.php. The application fails to sanitize user-supplied input before using it in a system-level context. Remote, unauthenticated attackers can inject shell commands by appending them to the plot parameter (e.g., ?plot=;id) in a crafted GET request. The output of the command is displayed in the application's interface after interacting with the host selection UI. Successful exploitation leads to arbitrary command execution on the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-04 UTC.

EPSS 60.30% · 99.1th percentile

Risk Scores

CVSS 4.0
10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score
60.30%
99.1th percentile

Affected Products

VendorProductVersions
sar2htmlsar2html0

Timeline

  • Sep 27, 2022 CrowdSec Sighting
  • Dec 4, 2022 CrowdSec Sighting
  • Apr 5, 2023 CrowdSec Sighting
  • Jun 20, 2025 CVE Published
  • Jun 20, 2025 PoC Published
  • Jun 21, 2025 EPSS Score
  • Jun 21, 2025 PoC Published
  • Jun 28, 2025 CrowdSec Sighting
  • Jul 1, 2025 EPSS Score
  • Jul 11, 2025 EPSS Score
  • Jul 22, 2025 EPSS Score
  • Aug 11, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›