ZeroHour

CVE-2019-9617

PoC
CVSS 3.0
8.8 high
EPSS
3%p85
Published
()
Modified
Description

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadFile URI.

Vendors
ofcms project
Products
ofcms
Weakness
CWE-434
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.