Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Tree Chiu

Pesquisador deCHT Security
#22424de 53,632
10CVSS total
Vulnerabilidades · 1
PT-2019-12159
10
2019-07-11
Sunnet · Sunnet Wmpro · CVE-2019-11062
**Name of the Vulnerable Software and Affected Versions** SUNNET WMPro versions 5.0 through 5.1 **Description** The issue concerns an OS Command Injection vulnerability. It can be exploited via the "/teach/course/doajaxfileupload.php" API endpoint without requiring authentication. **Recommendations** For versions 5.0 and 5.1, consider restricting access to the "/teach/course/doajaxfileupload.php" API endpoint until a patch is available. As a temporary workaround, disabling the functionality related to this endpoint may help minimize the risk of exploitation.