10
CVSSv2

CVE-2019-15751

Published: 07/10/2019 Updated: 09/10/2019
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An unrestricted file upload vulnerability in SITOS six Build v6.2.1 allows remote malicious users to execute arbitrary code by uploading a SCORM file with an executable extension. This allows an unauthenticated malicious user to upload a malicious file (containing PHP code to execute operating system commands) to the web root of the application.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sitos sitos six 6.2.1