SITOS six Build v6.2.1 permits unauthorised users to upload and import a SCORM 2004 package by browsing directly to affected pages. An unauthenticated attacker could use the upload and import functionality to import a malicious SCORM package that includes a PHP file, which could execute arbitrary PHP code.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-10-07T11:40:15

Updated: 2024-08-05T00:56:22.322Z

Reserved: 2019-08-28T00:00:00

Link: CVE-2019-15748

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-10-07T12:15:11.367

Modified: 2019-10-09T00:16:12.877

Link: CVE-2019-15748

cve-icon Redhat

No data.