Product Referenceproduct
https://codecanyon.net/item/signer-create-digital-signatures-and-sign-pdf-documents-online/20737707 CVE-2019-25729
CRITICAL
PDF Signer 3.0 Server-Side Template Injection RCE via CSRF Cookie
Record summary
CVE-2019-25729 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.
Description
PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP commands through the CSRF-TOKEN cookie parameter. Attackers can craft malicious cookie values containing template injection payloads like shell_exec() to execute system commands and retrieve sensitive information from the server.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 4, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
PDF SignerBrowse simcy_creative / PDF Signer | CVE List | 3.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBPDF Signer 3.0 - Server-Side Template Injection leading to Remote Command Execution (via Cross-Site Request Forgery Cookie)ExploitDB exploitby dd_Not analyzed1 file
References
5Official Product Homepageproduct
https://codecanyon.net/user/simcy_creative nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25729 ExploitDB-46276exploit
https://www.exploit-db.com/exploits/46276 VulnCheck Advisory: PDF Signer 3.0 Server-Side Template Injection RCE via CSRF CookieThird-party advisory
https://www.vulncheck.com/advisories/pdf-signer-server-side-template-injection-rce-via-csrf-cookie