CVE-2019-18211

CVE-2019-18211

An issue was discovered in Orckestra C1 CMS through 6.6. The EntityTokenSerializer class in Composite.dll is prone to unvalidated deserialization of wrapped BinaryFormatter payloads, leading to arbitrary remote code execution for any low-privilege user.

Source: CVE-2019-18211

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다