This thesis aims to provide a detailed analysis of the vulnerability identified as CVE-2025-32778, concerning the presence of an OS Command Injection weakness within the Web Check application. Initially, the screenshot capture functionality was examined, identifying in the source code the implementation flaw that allowed the arbitrary injection of system commands. Subsequently, an isolated test environment was set up using a Docker container to carry out the attacks in a controlled manner. In particular, a reverse shell was executed, followed by the launch of a phishing attack, which made it possible to compromise the digital identities of all users who logged in. Then , the same attacks were repeated on the corrected version of the application, where, thanks to the patch released, they had no effect. This study therefore confirms how important it is to consider security as a fundamental requirement in the software lifecycle, demonstrating how even the slightest oversight during the development phase can have very serious consequences for the confidentiality, integrity and availability of data. Keywords: Cybersecurity, Web Security, CVE-2025-32778, OS Command Injection, Reverse Shell, Phishing.

La presente tesi è volta a fornire un’analisi dettagliata della vulnerabilità identificata come CVE-2025-32778, riguardante la presenza di una debolezza del tipo OS Command Injection all’interno dell’applicativo Web Check. Inizialmente, è stata esaminata la funzionalità di acquisizione dello screenshot, identificando nel codice sorgente il difetto implementativo che consentiva l’iniezione arbitraria di comandi di sistema. Dopodiché, è stato realizzato un ambiente di test isolato tramite container Docker per condurre gli attacchi in modo controllato. In particolare, è stata eseguita una Reverse Shell per poi impostare un attacco di phishing, grazie al quale è stato possibile compromettere l’identità digitale di tutti gli utenti che effettuassero l’accesso. Successivamente, sono stati ripetuti i medesimi attacchi anche sulla versione corretta dell’applicativo, in cui, grazie alla patch rilasciata, essi non hanno avuto effetto. Tale studio offre dunque una conferma di quanto sia importante considerare la sicurezza come requisito fondamentale nel ciclo di vita del software, dimostrando come anche una minima disattenzione in fase di sviluppo possa determinare conseguenze assai gravi per la riservatezza, l’integrità e la disponibilità dei dati. Keywords: Cybersecurity, Web Security, CVE-2025-32778, OS Command Injection, Reverse Shell, Phishing.

SFRUTTAMENTO DELLA VULNERABILITÀ CVE-2025-32778 PER LA COMPROMISSIONE DELL’IDENTITÀ DIGITALE

BALDONCINI, MATTEO
2025/2026

Abstract

This thesis aims to provide a detailed analysis of the vulnerability identified as CVE-2025-32778, concerning the presence of an OS Command Injection weakness within the Web Check application. Initially, the screenshot capture functionality was examined, identifying in the source code the implementation flaw that allowed the arbitrary injection of system commands. Subsequently, an isolated test environment was set up using a Docker container to carry out the attacks in a controlled manner. In particular, a reverse shell was executed, followed by the launch of a phishing attack, which made it possible to compromise the digital identities of all users who logged in. Then , the same attacks were repeated on the corrected version of the application, where, thanks to the patch released, they had no effect. This study therefore confirms how important it is to consider security as a fundamental requirement in the software lifecycle, demonstrating how even the slightest oversight during the development phase can have very serious consequences for the confidentiality, integrity and availability of data. Keywords: Cybersecurity, Web Security, CVE-2025-32778, OS Command Injection, Reverse Shell, Phishing.
2025
2026-07-16
EXPLOITING THE CVE-2025-32778 VULNERABILITY FOR DIGITAL IDENTITY COMPROMISE
La presente tesi è volta a fornire un’analisi dettagliata della vulnerabilità identificata come CVE-2025-32778, riguardante la presenza di una debolezza del tipo OS Command Injection all’interno dell’applicativo Web Check. Inizialmente, è stata esaminata la funzionalità di acquisizione dello screenshot, identificando nel codice sorgente il difetto implementativo che consentiva l’iniezione arbitraria di comandi di sistema. Dopodiché, è stato realizzato un ambiente di test isolato tramite container Docker per condurre gli attacchi in modo controllato. In particolare, è stata eseguita una Reverse Shell per poi impostare un attacco di phishing, grazie al quale è stato possibile compromettere l’identità digitale di tutti gli utenti che effettuassero l’accesso. Successivamente, sono stati ripetuti i medesimi attacchi anche sulla versione corretta dell’applicativo, in cui, grazie alla patch rilasciata, essi non hanno avuto effetto. Tale studio offre dunque una conferma di quanto sia importante considerare la sicurezza come requisito fondamentale nel ciclo di vita del software, dimostrando come anche una minima disattenzione in fase di sviluppo possa determinare conseguenze assai gravi per la riservatezza, l’integrità e la disponibilità dei dati. Keywords: Cybersecurity, Web Security, CVE-2025-32778, OS Command Injection, Reverse Shell, Phishing.
File in questo prodotto:
File Dimensione Formato  
Tesi_Triennale_Matteo_Baldoncini_online-1.pdf

accesso aperto

Descrizione: La presente tesi è volta a fornire un’analisi dettagliata della vulnerabilità identificata come CVE-2025-32778, riguardante la presenza di una debolezza del tipo OS Command Injection all’interno dell’applicativo Web Check.
Dimensione 1.2 MB
Formato Adobe PDF
1.2 MB Adobe PDF Visualizza/Apri

I documenti in UNITESI sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.12075/27273