CRITICAL

CVE-2019-16885

CVSS v3

9.8

CRITICAL

EPSS Score

16.9%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

In OkayCMS through 2.3.4, an unauthenticated attacker can achieve remote code execution by injecting a malicious PHP object via a crafted cookie. This could happen at two places: first in view/ProductsView.php using the cookie price_filter, and second in api/Comparison.php via the cookie comparison.

Technical details

Published
12/3/2019

Frequently asked questions

What is CVE-2019-16885?

In OkayCMS through 2.3.4, an unauthenticated attacker can achieve remote code execution by injecting a malicious PHP object via a crafted cookie. This could happen at two places: first in view/ProductsView.php using the cookie price_filter, and second in api/Comparison.php via the cookie comparison.

Is CVE-2019-16885 actively exploited?

Active exploitation of CVE-2019-16885 has not been confirmed. The EPSS score is 16.9%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-16885?

CVE-2019-16885 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2019-16885 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.