Vulnerability Description
The SUNNET WMPro v5.0 and v5.1 for eLearning system has OS Command Injection via "/teach/course/doajaxfileupload.php". The target server can be exploited without authentication.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sun.Net | Wmpro | 5.0 |
Related Weaknesses (CWE)
References
- http://surl.twcert.org.tw/hLFFMBroken Link
- https://gist.github.com/tonykuo76/476164af9bc672281b9a3394f01c17f0ExploitThird Party Advisory
- https://tvn.twcert.org.tw/taiwanvn/TVN-201906001Third Party Advisory
- http://surl.twcert.org.tw/hLFFMBroken Link
- https://gist.github.com/tonykuo76/476164af9bc672281b9a3394f01c17f0ExploitThird Party Advisory
- https://tvn.twcert.org.tw/taiwanvn/TVN-201906001Third Party Advisory
FAQ
What is CVE-2019-11062?
CVE-2019-11062 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The SUNNET WMPro v5.0 and v5.1 for eLearning system has OS Command Injection via "/teach/course/doajaxfileupload.php". The target server can be exploited without authentication.
How severe is CVE-2019-11062?
CVE-2019-11062 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-11062?
Check the references section above for vendor advisories and patch information. Affected products include: Sun.Net Wmpro.