CVE-2025-35113
Agiloft improper neutralization in EUI template engine
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.8EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
26 Aug 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Agiloft Release 28 does not properly neutralize special elements used in an EUI template engine, allowing an authenticated attacker to achieve remote code execution by loading a specially crafted payload. Users should upgrade to Agiloft Release 31.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L
Affected products
Agiloft · AgiloftWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →