Back to CVE List

CVE-2018-25159

CRITICAL SEVERITY

CVSS Score & Metrics

Base Score
9.8 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Description

Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by injecting malicious OGNL expressions. Attackers can send crafted requests to the login.action endpoint with OGNL payloads in the redirect parameter to instantiate ProcessBuilder objects and execute system commands with root privileges.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-1334
Source
NVD
Vendor
Epross
Product
AVCON6 systems management platform

External References

Discussion (0)

Add Comment

No comments yet. Be the first!