VYPR
Critical severity9.8NVD Advisory· Published Feb 9, 2019· Updated Jun 17, 2026

CVE-2019-7684

CVE-2019-7684

Description

inxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file. The vulnerable code location is com.inxedu.os.common.controller.VideoUploadController#gok4 (com/inxedu/os/common/controller/VideoUploadController.java). The attacker uses the /video/uploadvideo fileType parameter to change the list of acceptable extensions from jpg,gif,png,jpeg to jpg,gif,png,jsp,jpeg.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Inxedu/Inxeduinferred3 versions
    <= 2018-12-24+ 2 more
    • (no CPE)range: <= 2018-12-24
    • cpe:2.3:a:inxedu:inxedu:*:*:*:*:*:*:*:*range: <=2018-12-24
    • (no CPE)range: <=2018-12-24

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.