Product: PocketVJ CP
Affected Versions: pvj 3.9.1
Vulnerability Type: Remote Code Execution (RCE)
Description:
An issue in PocketVJ CP PocketVJ-CP-v3 pvj 3.9.1 allows remote attackers to execute arbitrary code via the submit_size.php component. The vulnerable code uses shell_exec(), exec(), and system() functions without proper sanitization.
Attack Vector: