Search Results (Refine Search)
- CPE Product Version: cpe:/a:chatopera:cosin:3.10.0
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2019-6503 |
There is a deserialization vulnerability in Chatopera cosin v3.10.0. An attacker can execute commands during server-side deserialization by uploading maliciously constructed files. This is related to the TemplateController.java impsave method and the MainUtils toObject method. Published: January 22, 2019; 9:29:00 AM -0500 |
V3.0: 9.8 CRITICAL V2.0: 7.5 HIGH |