Arbitrary Code Execution Vulnerability in SiteServer CMS 6.9.0

Arbitrary Code Execution Vulnerability in SiteServer CMS 6.9.0

CVE-2019-11401 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:P/A:P

A issue was discovered in SiteServer CMS 6.9.0. It allows remote attackers to execute arbitrary code because an administrator can add the permitted file extension .aassp, which is converted to .asp because the "as" substring is deleted.

Learn more about our Cis Benchmark Audit For Server Software.