VYPR
Critical severity10.0NVD Advisory· Published Apr 28, 2025· Updated Jun 17, 2026

CVE-2025-46661

CVE-2025-46661

Description

IPW Systems Metazo through 8.1.3 allows unauthenticated Remote Code Execution because smartyValidator.php enables the attacker to provide template expressions, aka Server-Side Template-Injection. All instances have been patched by the Supplier.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • IPW/Metazov5
    Range: 0
  • IPW Systems/Metazollm-fuzzy2 versions
    <=8.1.3+ 1 more
    • (no CPE)range: <=8.1.3
    • cpe:2.3:a:ipwsystems:metazo:*:*:*:*:*:*:*:*range: <=8.1.13

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.