VDB

CVE-2019-14466

CVE-2019-14466 PUBLISHED CVSS 6.5 MEDIUM

The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote authenticated attacker to perform file deletions (in the context of the user account that runs the web server) via a crafted cookie value, because unserialize is used to restore filter settings from a cookie.

EPSS 1.18% · 66.5th percentile

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS Score
1.18%
66.5th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSgosa0, 2.7.4+reloaded2-13ubuntu1, 2.7.4+reloaded3-3
Ubuntu:16.04:LTSgosa2.7.4+reloaded2-7, 2.7.4+reloaded2-8, 0

Timeline

  • Dec 31, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 25, 2021 EPSS Score
  • Dec 29, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 3, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 5, 2022 EPSS Score
  • Sep 9, 2022 EPSS Score
  • Nov 11, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›