Arbitrary Code Execution Vulnerability in Indexhibit 2.1.5

Arbitrary Code Execution Vulnerability in Indexhibit 2.1.5

CVE-2019-8954 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:P/A:P

In Indexhibit 2.1.5, remote attackers can execute arbitrary code via the v parameter (in conjunction with the id parameter) in a upd_jxcode=true action to the ndxzstudio/?a=system URI.

Learn more about our Web Application Penetration Testing UK.