name:Unauthenticated RCE at Mida eFramework on 'PDC/ajaxreq.php'
author:dwisiswant0
severity:critical
description:There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. No authentication is required.