CVE-2019-6503

There is a deserialization vulnerability in Chatopera cosin v3.10.0. An attacker can execute commands during server-side deserialization by uploading maliciously constructed files. This is related to the TemplateController.java impsave method and the MainUtils toObject method.
References
Link Resource
https://github.com/chatopera/cosin/issues/177 Third Party Advisory Issue Tracking Exploit
Configurations

Configuration 1 (hide)

cpe:2.3:a:chatopera:cosin:3.10.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-01-22 14:29

Updated : 2019-02-15 18:33


NVD link : CVE-2019-6503

Mitre link : CVE-2019-6503

CVE.ORG link : CVE-2019-6503


JSON object : View

Products Affected

chatopera

  • cosin
CWE
CWE-502

Deserialization of Untrusted Data