CVE-2019-18211
HIGHOrckestra C1 Cms < 6.6 - Insecure Deserialization
Title source: ruleDescription
An issue was discovered in Orckestra C1 CMS through 6.6. The EntityTokenSerializer class in Composite.dll is prone to unvalidated deserialization of wrapped BinaryFormatter payloads, leading to arbitrary remote code execution for any low-privilege user.
Scores
CVSS v3
8.8
EPSS
0.0281
EPSS Percentile
86.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (1)
orckestra/c1_cms
< 6.6
Timeline
Published
Dec 23, 2019
Tracked Since
Feb 18, 2026