High severity7.2OSV Advisory· Published Apr 22, 2019· Updated Jun 17, 2026
CVE-2019-11401
CVE-2019-11401
Description
A issue was discovered in SiteServer CMS 6.9.0. It allows remote attackers to execute arbitrary code because an administrator can add the permitted file extension .aassp, which is converted to .asp because the "as" substring is deleted.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
sscmsNuGet | < 6.12 | 6.12 |
Affected products
3- Range: siteserver-dev-v5.0.18, siteserver-dev-v5.0.22, siteserver-dev-v5.0.23, …
- cpe:2.3:a:siteserver:siteserver_cms:6.9.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- github.com/siteserver/cms/issues/1858nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-ff4w-8chr-w2x9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-11401ghsaADVISORY
- github.com/siteserver/cms/commit/a7edb9ce3f9b52be3d18fa8a0e44931264e22436ghsaWEB
News mentions
0No linked articles in our index yet.