CVE-2025-6839 Details
Description
A vulnerability, which was classified as critical, has been found in Conjure Position Department Service Quality Evaluation System up to 1.0.11. Affected by this issue is the function eval of the file public/assets/less/bootstrap-less/mixins/head.php. The manipulation of the argument payload leads to backdoor. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
A critical backdoor vulnerability has been identified in Conjure Position Department Service Quality Evaluation System versions through 1.0.11. The issue resides in the 'eval' function of the file 'public/assets/less/bootstrap-less/mixins/head.php'. This vulnerability allows remote code execution by manipulating the 'payload' argument, with the backdoor's presence disguised within a legitimate asset file.
Users are advised to remove the malicious 'head.php' file and check for similar backdoors in other directories. Reviewing web server access logs for suspicious POST requests to this file is also recommended. Changing administrative passwords and API keys, invalidating active user sessions, and implementing long-term security measures such as a secure development lifecycle and regular penetration testing can help prevent future incidents.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 29, 2025CISA-ADP
Assessed Jun 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://note-hxlab.wetolink.com/share/LZJIef0phS6B | [email protected] | ExploitTechnical Analysis |
| https://note-hxlab.wetolink.com/share/LZJIef0phS6B#proof-of-concept- | [email protected] | ExploitRemedy |
| https://vuldb.com/?ctiid.314282 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.314282 | [email protected] | AdvisoryExploit |
| https://vuldb.com/?submit.603176 | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-912 | Hidden Functionality | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Conjure Position Department Service Quality Evaluation System | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Jun 29, 2025 | New CVE Received | [email protected] |
Volerion