CVE-2019-12744 – SeedDMS / SeedDMS – Unrestricted file upload

CVE-2019-12744 is an unrestricted file upload vulnerability impacting SeedDMS versions 5.1.10 and earlier. An exploit was observed in open source and a link to an exploit was shared in the underground.

Summary:

CVE-2019-12744 is an unrestricted file upload vulnerability impacting SeedDMS versions 5.1.10 and earlier. An exploit was observed in open source and a link to an exploit was shared in the underground.

PoC Links(if available):

Exploit DB link –
https://www.exploit-db.com/exploits/50062

Known Counter Measures:

SeedDMS addressed the vulnerability in SeedDMS version 5.1.11.

Links to patches(if available)

https://sourceforge.net/p/seeddms/code/ci/master/tree/CHANGELOG