PT-2018-14984 · Httl · Httl
Xqc2000
·
Published
2018-11-26
·
Updated
2018-12-19
·
CVE-2018-19531
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
HTTL versions through 1.0.11
Description
The issue allows remote command execution due to the unsafe use of java.beans.XMLEncoder by the decodeXml function when configured without an xml.codec setting.
Recommendations
For versions through 1.0.11, consider configuring the xml.codec setting to prevent the unsafe use of java.beans.XMLEncoder until a patch is available.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Httl