CVE-2019-6503

There is a deserialization vulnerability in Chatopera cosin v3.10.0. An attacker can execute commands during server-side deserialization by uploading maliciously constructed files. This is related to the TemplateController.java impsave method and the MainUtils toObject method.
References
Link Resource
https://github.com/chatopera/cosin/issues/177 Third Party Advisory Issue Tracking
Configurations

Configuration 1

cpe:2.3:a:chatopera:cosin:3.10.0:*:*:*:*:*:*:*

Information

Published : 2019-01-22 02:29

Updated : 2019-02-15 06:33


NVD link : CVE-2019-6503

Mitre link : CVE-2019-6503

Products Affected
No products.
CWE
CWE-502

Deserialization of Untrusted Data