CVE-2025-32778
Web-Check allows command Injection via Unvalidated URL in Screenshot API
Vexday Risk Score
68Prioridad alta
Decisión SSVC (CISA)
Attend
PoC disponible → seguir de cerca
CVSS 9.3EPSS 20.0%KEV nãoPoC públicaNuclei simMetasploit simPatch —
Ciclo de vida
12 abr 2025Exploit Metasploit disponible
15 abr 2025Publicada en NVD
17 ago 2025PoC pública
Recomendación: Planificar corrección próxima — ya existe PoC pública.
Web-Check is an all-in-one OSINT tool for analyzing any website. A command injection vulnerability exists in the screenshot API of the Web Check project (Lissy93/web-check). The issue stems from user-controlled input (url) being passed unsanitized into a shell command using exec(), allowing attackers to execute arbitrary system commands on the underlying host. This could be exploited by sending crafted url parameters to extract files or even establish remote access. The vulnerability has been patched by replacing exec() with execFile(), which avoids using a shell and properly isolates arguments.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
Lissy93 · web-checkPoCs públicas encontradas — 1
githubgithub.com/00xCanelo/CVE-2025-32778★ 3⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →