Impact
R‑SOFT DMS contains an OS Command Injection flaw in the konwertujAction() function. The document converter builds and executes shell commands by interpolating unvalidated file paths and format parameters. An attacker who can authenticate to the web application can therefore supply crafted inputs that cause the server to run arbitrary commands with the privileges of the web server user, enabling data exfiltration, compromise of the underlying operating system, or further lateral movement within the host environment.
Affected Systems
The vulnerability affects all versions of R‑SOFT SERWIS DMS prior to the releases that contain the fix – v3.19‑2752 and v3.17‑2580. Any installation of DMS that has not been updated to one of these versions is susceptible to exploitation.
Risk and Exploitability
The flaw carries a high CVSS score of 8.7 and an EPSS score of 1%, indicating a low but non‑zero likelihood of exploitation in the current environment. It is not listed in the CISA KEV catalog. Because the attack requires only authentication to the web interface and uses the konwertujAction() endpoint, an attacker who gains valid credentials can readily execute arbitrary code as the web server process. There are no special environment constraints beyond the presence of the vulnerable endpoint, making this a straightforward high‑risk vulnerability.
OpenCVE Enrichment