CVE-2025-30057
Authenticated RCE with uhcapache privileges in ConvertToPDF
In UHCRTFDoc, the filename parameter can be exploited to execute arbitrary code via command injection into the system() call in the ConvertToPDF function.
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Affected products
CGM · CGM CLININETWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →