PT-2019-18123 · Chatopera · Chatopera Cosin

Publicado

2019-01-22

·

Atualizado

2019-02-15

·

CVE-2019-6503

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chatopera cosin version 3.10.0
Description The issue is related to a deserialization vulnerability. An attacker can execute commands during server-side deserialization by uploading maliciously constructed files. This vulnerability is associated with the TemplateController.java impsave method and the MainUtils toObject method.
Recommendations For Chatopera cosin version 3.10.0, consider disabling the impsave method in TemplateController.java and restricting the use of the toObject method in MainUtils until a patch is available. Avoid uploading files from untrusted sources to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-6503

Produtos afetados

Chatopera Cosin