CVE-2019-25714
Last modified
CVE-2019-25714 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyon/htmlofficeservlet endpoint that allows remote attackers to write arbitrary files to the web application root by sending specially crafted POST requests with custom base64-encoded payloads. Attackers can write JSP webshells to the web root and execute them through the web server to achieve arbitrary OS command execution with web server privileges. Exploitation evidence was first observed by the Shadowserver Foundation on 2021-03-26 (UTC).. EPSS estimates a 0.65% chance of exploitation in the next 30 days.
Description
Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyon/htmlofficeservlet endpoint that allows remote attackers to write arbitrary files to the web application root by sending specially crafted POST requests with custom base64-encoded payloads. Attackers can write JSP webshells to the web root and execute them through the web server to achieve arbitrary OS command execution with web server privileges. Exploitation evidence was first observed by the Shadowserver Foundation on 2021-03-26 (UTC).
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2019-25714?
How severe is CVE-2019-25714?
How do I fix CVE-2019-25714?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-25709CF Image Hosting Script 1.6.5 allows unauthenticated attacke…9.8
- CVE-2019-2571Vulnerability in the RDBMS DataPump component of Oracle Data…
- CVE-2019-25710Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerabili…9.1
- CVE-2019-25711SpotFTP Password Recover 2.4.2 contains a denial of service …5.5
- CVE-2019-25712BlueAuditor 1.7.2.0 contains a buffer overflow vulnerability…5.5
- CVE-2019-25713MyT-PM 1.5.1 contains an SQL injection vulnerability that al…8.1
- CVE-2019-25716Dräger Infinity Delta, Delta XL, and Kappa patient monitors …7.5
- CVE-2019-25717Dräger Infinity Delta, Delta XL, and Kappa patient monitors …5.3
- CVE-2019-25718Dräger Infinity Explorer C700 contains a privilege escalatio…7.8
- CVE-2019-25719Dräger Infinity Acute Care System and Standalone Infinity M5…8.8
- CVE-2019-2572Vulnerability in the Oracle SOA Suite component of Oracle Fu…
- CVE-2019-25720Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000,…7.1
Are you affected by CVE-2019-25714?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
