PT-2019-18123 · Chatopera · Chatopera Cosin
Published
2019-01-22
·
Updated
2019-02-15
·
CVE-2019-6503
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Chatopera cosin version 3.10.0
Description
The issue is related to a deserialization vulnerability. An attacker can execute commands during server-side deserialization by uploading maliciously constructed files. This vulnerability is associated with the
TemplateController.java impsave method and the MainUtils toObject method.Recommendations
For Chatopera cosin version 3.10.0, consider disabling the
impsave method in TemplateController.java and restricting the use of the toObject method in MainUtils until a patch is available. Avoid uploading files from untrusted sources to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chatopera Cosin