VYPR

Cosin

by Chatopera

Source repositories

CVEs (1)

  • CVE-2019-6503Jan 22, 2019
    risk 0.00cvss epss 0.00

    There is a deserialization vulnerability in Chatopera cosin v3.10.0. An attacker can execute commands during server-side deserialization by uploading maliciously constructed files. This is related to the TemplateController.java impsave method and the MainUtils toObject method.