Vulnerabilities > Altavoz

DATE CVE VULNERABILITY TITLE RISK
2019-08-26 CVE-2019-15503 OS Command Injection vulnerability in Altavoz Prontuscms 11.2.101/12.0.3.0
cgi-cpn/xcoding/prontus_videocut.cgi in AltaVoz Prontus (aka ProntusCMS) through 12.0.3.0 has "Improper Neutralization of Special Elements used in an OS Command," allowing attackers to execute OS commands via an HTTP GET parameter.
network
low complexity
altavoz CWE-78
critical
9.8