{ "schema_version": "1.4.0", "id": "GHSA-fv76-64ff-h2vm", "modified": "2022-05-24T16:46:07Z", "published": "2022-05-24T16:46:07Z", "aliases": [ "CVE-2019-12185" ], "details": "eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may result in remote command execution. An attacker can use a user account to fully compromise the system using a POST request. This will allow for PHP files to be written to the web root, and for code to execute on the remote server.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-12185" }, { "type": "WEB", "url": "https://github.com/fuzzlove/eLabFTW-1.8.5-EntityController-Arbitrary-File-Upload-RCE" }, { "type": "WEB", "url": "http://incidentsecurity.com/elabftw-1-8-5-entitycontroller-arbitrary-file-upload-rce" } ], "database_specific": { "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-05-20T00:29:00Z" } }