CVE-2025-34102General

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A remote code execution vulnerability exists in CryptoLog (PHP version, discontinued since 2009) due to a chained exploitation of SQL injection and command injection vulnerabilities. An unauthenticated attacker can gain shell access as the web server user by first exploiting a SQL injection flaw in login.php to bypass authentication, followed by command injection in logshares_ajax.php to execute arbitrary operating system commands. The login bypass is achieved by submitting crafted SQL via the user POST parameter. Once authenticated, the attacker can abuse the lsid POST parameter in the logshares_ajax.php endpoint to inject and execute a command using $(...) syntax, resulting in code execution under the web context. This exploitation path does not exist in the ASP.NET version of CryptoLog released since 2009.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-78CWE-89CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-07: 1PoC Mentioned / Linked · 2026-04-07: 1Technical Details · 2026-04-07: 104-07
Signal classification1 categories
General
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • 0day Signal@0dayPublishing
    General

    🚨 CVE-2025-34102: CryptoLog Unauthenticated RCE vi... SQL-to-shell chain in legacy CryptoLog turns any web-facing instance into instant pwn - login.php bypass + logshares_aj... https://zerodaysignal.com/vulnerability/CVE-2025-34102 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2025-34102 exposes an unauthenticated RCE in CryptoLog via an SQL-to-shell chain that bypasses login.php, but no public PoC, exploit code, patch, or active exploitation details are provided.

    00000258
    204 followersView on X

Explore more