An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execute arbitrary commands on the underlying operating system and achieve remote code execution.Credits@VolpinaReginaCSIRT-ITReferenceshttps://www.trexom.net/sviluppo-di-app/https://www.acn.gov.it/portale/w/trexom-aggiornamenti-di-sicurezza