CVE-2018-25135

CRITICAL

Anviz AIM CrossChex Standard 4.3.6.0 - Code Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-25135. PoCs published by LiquidWorm.

AI-analyzed exploit summary This exploit demonstrates CSV injection in Anviz AIM CrossChex Standard 4.3, allowing arbitrary command execution via Excel macro formulas inserted into user fields. The PoC shows how an attacker can trigger command execution (e.g., launching mspaint) by manipulating the 'Name' or custom fields during user import/export.

Description

Anviz AIM CrossChex Standard 4.3.6.0 contains a CSV injection vulnerability that allows attackers to execute commands by inserting malicious formulas in user import fields. Attackers can craft payloads in fields like 'Name', 'Gender', or 'Position' to trigger Excel macro execution when importing user data.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textlocalwindows
https://www.exploit-db.com/exploits/45765

This exploit demonstrates CSV injection in Anviz AIM CrossChex Standard 4.3, allowing arbitrary command execution via Excel macro formulas inserted into user fields. The PoC shows how an attacker can trigger command execution (e.g., launching mspaint) by manipulating the 'Name' or custom fields during user import/export.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Anviz AIM CrossChex Standard 4.3.6.0
Auth required
Prerequisites: Access to the application's user management interface · Ability to import/export user data via Excel files
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/45765
Various Sources product
https://www.anviz.com
Third Party Advisory third-party-advisory
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5498.php

Scores

CVSS v3 9.8
EPSS 0.0059
EPSS Percentile 43.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-149
Status published
Products (1)
Anviz Biometric Technology Co., Ltd./Anviz AIM CrossChex Standard 4.3
Published Dec 24, 2025
Tracked Since Feb 18, 2026