CVE-2020-12471

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
29/04/2020
Last modified:
04/05/2020

Description

MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or Pages/SocialNetworking/lng/en-US/PhotoGallery.aspx because of deserialization in ModuleGallery.HTML5Upload, ModuleGallery.SilverLightUploadModule, HTML5Upload, and SilverLightUploadHandler.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mono:monox:*:*:*:*:*:*:*:* 5.1.40.5152 (including)