First published: Mon Mar 25 2019(Updated: )
Jenzabar JICS (aka Internet Campus Solution) before 9 allows remote attackers to upload and execute arbitrary .aspx code by placing it in a ZIP archive and using the MoxieManager (for .NET) plugin before 2.1.4 in the moxiemanager directory within the installation folder ICS\ICS.NET\ICSFileServer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenzabar Internet Campus Solution | =9 | |
Tiny Moxiemanager | <2.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10012 is a vulnerability in Jenzabar JICS that allows remote attackers to upload and execute arbitrary .aspx code.
Remote attackers can exploit CVE-2019-10012 by placing arbitrary .aspx code in a ZIP archive and using the MoxieManager (for .NET) plugin before 2.1.4 in the moxiemanager directory within the installation folder ICS\ICS.NET\ICSFileServer.
CVE-2019-10012 has a severity rating of 7.5 (high).
Jenzabar Internet Campus Solution version 9 and Tiny Moxiemanager version up to 2.1.4 are affected by CVE-2019-10012.
The recommended fix for CVE-2019-10012 is to update Jenzabar JICS to a version where this vulnerability has been patched.