cve/2019/CVE-2019-9617.md
2025-09-29 21:09:30 +02:00

688 B

CVE-2019-9617

Description

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadFile URI.

POC

Reference

Github

No PoCs found on GitHub currently.