SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a different vulnerability than CVE-2018-12940.
References
Configurations
History
No history.
Information
Published : 2019-06-20 17:15
Updated : 2024-11-21 04:23
NVD link : CVE-2019-12744
Mitre link : CVE-2019-12744
CVE.ORG link : CVE-2019-12744
JSON object : View
Products Affected
seeddms
- seeddms
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type