PT-2019-19753 · Ofcms · Ofcms

匿名

·

Published

2019-03-06

·

Updated

2021-07-21

·

CVE-2019-9614

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OFCMS versions prior to 1.1.3
Description A command execution issue exists in OFCMS. This issue can be exploited via a template file using the freemarker.template.utility.Execute function, allowing an attacker to execute arbitrary commands. The exploitation involves using the ${ ex("} syntax followed by the command.
Recommendations For versions prior to 1.1.3, update to version 1.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to template files or disabling the use of the freemarker.template.utility.Execute function until a patch is applied. Avoid using the ex variable in template files to minimize the risk of exploitation.

Exploit

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-9614

Affected Products

Ofcms