ZeroHour

CVE-2019-9613

PoC
CVSS 3.0
7.2 high
EPSS
3%p85
Published
()
Modified
Description

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadVideo URI.

Vendors
ofcms project
Products
ofcms
Weakness
CWE-434
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.