Impact
An attacker can modify the antivirus binary path configuration in Xerte Online Tools so that it points to a PHP interpreter instead of a legitimate antivirus program. When the path is altered, files uploaded to the server are treated as PHP code and executed by the web server process, providing the attacker with the ability to run arbitrary commands with the privileges of the web server and effectively compromising the entire system.
Affected Systems
The vulnerability affects Xerte Online Tools from the Xerte project. No specific product versions are listed in the CVE data; however, the references indicate that versions 3.14 and 3.15 received a security update, suggesting these releases may contain the fix.
Risk and Exploitability
The CVSS score of 9.8 categorizes the flaw as Critical, while the EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote: an adversary who can modify configuration settings or upload files can trigger the execution of injected PHP code.
OpenCVE Enrichment