IPW Systems Metazo Unauthenticated Remote Code Execution Vulnerability via Server-Side Template Injection

Vulnerability

A remote code execution vulnerability has been identified in IPW Systems Metazo versions through 8.1.3. The issue arises from the smartyValidator.php file, which allows attackers to inject template expressions, leading to server-side template injection. This vulnerability has been patched by the vendor.

Impact

Exploitation of this vulnerability allows for unauthenticated remote code execution on the server where IPW Systems Metazo is hosted.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.