CVE-2019-14466: Medium severity gosa vulnerability
The GOsaFilterSettings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote authenticated attacker to perform file deletions (in the context of the user account that runs the web server) via a crafted cookie value, because unserialize is used to restore filter settings from a cookie.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-14466.
What is the severity of CVE-2019-14466?
The severity of CVE-2019-14466 is medium with a score of 6.5.
Which software is affected by CVE-2019-14466?
GONICUS GOsa version 2.7.5.2 and Debian Linux version 8.0 are affected by CVE-2019-14466.
How does CVE-2019-14466 impact the affected software?
CVE-2019-14466 allows a remote authenticated attacker to perform file deletions in the context of the user account that runs the web server via a crafted cookie value.
Is there a fix available for CVE-2019-14466?
Yes, the fix for CVE-2019-14466 is available. Please refer to the provided references for more information on the fix.