CVE-2019-10012: Malicious File Upload
Jenzabar JICS (aka Internet Campus Solution) before 9 allows remote attackers to upload and execute arbitrary .aspx code by placing it in a ZIP archive and using the MoxieManager (for .NET) plugin before 2.1.4 in the moxiemanager directory within the installation folder ICS\ICS.NET\ICSFileServer.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-10012?
CVE-2019-10012 is a vulnerability in Jenzabar JICS that allows remote attackers to upload and execute arbitrary .aspx code.
How can remote attackers exploit CVE-2019-10012?
Remote attackers can exploit CVE-2019-10012 by placing arbitrary .aspx code in a ZIP archive and using the MoxieManager (for .NET) plugin before 2.1.4 in the moxiemanager directory within the installation folder ICS\ICS.NET\ICSFileServer.
What is the severity of CVE-2019-10012?
CVE-2019-10012 has a severity rating of 7.5 (high).
Which software versions are affected by CVE-2019-10012?
Jenzabar Internet Campus Solution version 9 and Tiny Moxiemanager version up to 2.1.4 are affected by CVE-2019-10012.
Is there a fix available for CVE-2019-10012?
The recommended fix for CVE-2019-10012 is to update Jenzabar JICS to a version where this vulnerability has been patched.