← Back

CVE-2019-18211

nvd nist
Published: Dec 23, 2019Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

An issue was discovered in Orckestra C1 CMS through 6.6. The EntityTokenSerializer class in Composite.dll is prone to unvalidated deserialization of wrapped BinaryFormatter payloads, leading to arbitrary remote code execution for any low-privilege user.

Affected (1)

Products: Orckestra: C1 Cms
1 product
C1 Cms
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 6.6

References (2)

Timeline

No history available yet.