CVE-2019-25024 | OpenRepeater up to 2.1 ajax_system.php post_service os command injection (EDB-52452)
A vulnerability, which was classified as critical, has been found in OpenRepeater up to 2.1. Affected by this issue is some unknown functionality of the file functions/ajax_system.php. The manipulation of the argument post_service leads to os command injection.
This vulnerability is documented as CVE-2019-25024. The attack requires being on the local network. Additionally, an exploit exists.
It is advisable to upgrade the affected component.