Security Advisory
CVE-2019-9613
7.2
HIGH
Vulnerability Description
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadVideo URI.
Published Date
March 6, 2019
Official Source
NIST NVD Advisory