Loading
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters.
Use CWE-78, Zeroshell vendor hub and Zeroshell product page to widen CVE-2019-12725 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2009-0545, CVE-2020-29390 and CVE-2021-41738 for nearby disclosures in the same product family.