Back

HIGH

OS Command Injection in R-SOFT DMS

Published Jul 10, 2026

Description

R-SOFT DMS is vulnerable to OS Command Injection in konwertujAction() function. The document converter executes shell commands using unsanitized file paths and format parameters. This allows an authenticated attacker to execute arbitrary system commands with the privileges of the web server user.

This issue was fixed in version v3.19-2752 and v3.17-2580.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner CERT-PL
Published Jul 10, 2026
Updated Jul 10, 2026
Reserved Apr 22, 2026

CISA Vulnrichment

Updated Jul 10, 2026

NVD

Status Deferred
Modified Jul 10, 2026

Red Hat

No data

ENISA EUVD

Assigner CERT-PL
Published Jul 10, 2026
Updated Jul 10, 2026

GitHub

No data