Description

An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost endpoint to unauthenticated users that is vulnerable to OS Command Injection. The endpoint takes an input parameter that is passed directly into the shell_exec() function of PHP. NOTE: this can be chained with CVE-2025-36845.

INFO

Published Date :

2025-07-21T00:00:00.000Z

Last Modified :

2025-07-21T19:05:38.118Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-36846 vulnerability.

Vendors Products
Eveo
  • Urve Web Manager
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-36846.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact