CVE-2019-15131

CRITICAL

Code42 < 6.7.5 - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

In Code42 Enterprise 6.7.5 and earlier, 6.8.4 through 6.8.8, and 7.0.0 a vulnerability has been identified that may allow arbitrary files to be uploaded to Code42 servers and executed. This vulnerability could allow an attacker to create directories and save files on Code42 servers, which could potentially lead to code execution.

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0113
EPSS Percentile 78.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (2)
code42/code42 7.0.0
code42/code42 < 6.7.5
Published Sep 17, 2019
Tracked Since Feb 18, 2026