CVE-2019-11062

CVE-2019-11062: SUNNET WMPro v5.0 and v5.1 has OS Command Injection

Vendor Sunnet
Product WMPro
Weakness CWE-78
Published July 11, 2019
Last update September 17, 2024

CVSS base score

What the vulnerability does

01Description

The SUNNET WMPro v5.0 and v5.1 for eLearning system has OS Command Injection via "/teach/course/doajaxfileupload.php". The target server can be exploited without authentication.

Key dates

02Disclosure timeline

July 11, 2019 CVE published
September 17, 2024 Record updated