Vulnerabilities > Rocketsoftware > Trufusion > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-12-01 CVE-2022-36431 Unrestricted Upload of File with Dangerous Type vulnerability in Rocketsoftware Trufusion
An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a crafted JSP file.
network
low complexity
rocketsoftware CWE-434
critical
9.8