CVE-2019-15131

CRITICAL

Code42 < 6.7.5, 6.8.4-6.8.8, 7.0.0 - Arbitrary File Upload and Remote Code Execution

Title source: llm
STIX 2.1

Description

In Code42 Enterprise 6.7.5 and earlier, 6.8.4 through 6.8.8, and 7.0.0 a vulnerability has been identified that may allow arbitrary files to be uploaded to Code42 servers and executed. This vulnerability could allow an attacker to create directories and save files on Code42 servers, which could potentially lead to code execution.

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0188
EPSS Percentile 76.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (2)
code42/code42 7.0.0
code42/code42 < 6.7.5
Published Sep 17, 2019
Tracked Since Feb 18, 2026