CVE-2020-12471: Critical severity mono vulnerability
MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or Pages/SocialNetworking/lng/en-US/PhotoGallery.aspx because of deserialization in ModuleGallery.HTML5Upload, ModuleGallery.SilverLightUploadModule, HTML5Upload, and SilverLightUploadHandler.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-12471?
CVE-2020-12471 has a high severity rating due to its ability to allow remote code execution.
How do I fix CVE-2020-12471?
To fix CVE-2020-12471, upgrade MonoX to version 5.1.40.5153 or later which addresses the deserialization vulnerability.
What systems are affected by CVE-2020-12471?
CVE-2020-12471 affects MonoX versions up to and including 5.1.40.5152.
What type of vulnerability is CVE-2020-12471?
CVE-2020-12471 is a remote code execution vulnerability caused by insecure deserialization.
What components are involved in CVE-2020-12471?
CVE-2020-12471 involves vulnerabilities in the ModuleGallery.HTML5Upload, ModuleGallery.SilverLightUploadModule, and other related handlers.