CVE-2025-65480

8.8

Pacom · Unison Client

Pacom Unison Client 5.13.1 allows authenticated users to inject malicious scripts into Report Templates, resulting in Remote Code Execution when specific conditions are met.

Executive summary

A high-severity vulnerability in Pacom Unison Client 5.13.1 allows authenticated attackers to execute arbitrary code via malicious script injection.

Vulnerability

This vulnerability involves an improper input validation flaw where authenticated users can inject malicious scripts into Report Templates. The injected code executes with the privileges of the application when certain script conditions are triggered, leading to Remote Code Execution.

Business impact

The ability to achieve Remote Code Execution poses a severe risk to organizational security, potentially allowing an attacker to gain full control over the affected system. Given the CVSS score of 8.8, this vulnerability could lead to significant data breaches, unauthorized lateral movement within the network, and complete compromise of the application environment.

Remediation

Immediate Action: Contact Pacom support or monitor the official vendor advisory portal for the release of a security patch addressing this Remote Code Execution flaw.

Proactive Monitoring: Review system and application logs for unusual activity related to the Report Template module or unexpected execution of scripts by the application service account.

Compensating Controls: Restrict access to the reporting functionality to only necessary personnel and implement strict input validation at the Web Application Firewall level if possible to block suspicious script patterns.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the vulnerability research provided by the referenced security report.

Analyst recommendation

Given the severity of this vulnerability and the existence of a public proof-of-concept, organizations should treat this as a high-priority item. Administrators must restrict user access to sensitive report-generation features immediately and prioritize the installation of vendor-supplied patches as soon as they are made available to prevent potential exploitation.

Sources