PT-2019-18123 · Chatopera · Chatopera Cosin
Publicado
2019-01-22
·
Atualizado
2019-02-15
·
CVE-2019-6503
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Chatopera cosin version 3.10.0
Description
The issue is related to a deserialization vulnerability. An attacker can execute commands during server-side deserialization by uploading maliciously constructed files. This vulnerability is associated with the
TemplateController.java impsave method and the MainUtils toObject method.Recommendations
For Chatopera cosin version 3.10.0, consider disabling the
impsave method in TemplateController.java and restricting the use of the toObject method in MainUtils until a patch is available. Avoid uploading files from untrusted sources to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Deserialization of Untrusted Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Chatopera Cosin