QSearchQSearch

CVE-2018-25320

9.8 CRITICAL

ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitra...

Published: 2026-05-17 · Last updated: 2026-05-18

Severity and scoring

CVSS
9.8 CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-94

Description

ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE function. Attackers can use bitsadmin to download malicious PowerShell scripts and execute them with system privileges to establish reverse shells and gain complete system control.

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-52860 Vim is an open source, command line text editor
  • CVE-2026-52858 Vim is an open source, command line text editor
  • CVE-2026-47167 Vim is an open source, command line text editor
  • CVE-2026-47162 Vim is an open source, command line text editor
  • CVE-2026-44495 Axios is a promise based HTTP client for the browser and Node.js (7.0 HIGH)