9.8
CVSSv3

CVE-2022-36431

Published: 01/12/2022 Updated: 05/12/2022
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise prior to 7.9.6.1 allows unauthenticated malicious users to execute arbitrary code via a crafted JSP file. Issue fixed in version 7.9.6.1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rocketsoftware trufusion