PT-2019-18123 · Chatopera · Chatopera Cosin

Published

2019-01-22

·

Updated

2019-02-15

·

CVE-2019-6503

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chatopera cosin version 3.10.0
Description The issue is related to a deserialization vulnerability. An attacker can execute commands during server-side deserialization by uploading maliciously constructed files. This vulnerability is associated with the TemplateController.java impsave method and the MainUtils toObject method.
Recommendations For Chatopera cosin version 3.10.0, consider disabling the impsave method in TemplateController.java and restricting the use of the toObject method in MainUtils until a patch is available. Avoid uploading files from untrusted sources to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-6503

Affected Products

Chatopera Cosin