codelibs Fess
cpe:2.3:a:codelibs:fess:*:*:*:*:*:*:*
- <= 15.5.1
A code injection vulnerability allowing remote code execution has been identified in Codelibs Fess versions through 15.5.1. The issue arises in the JSP File Handler component, specifically within the update function of the AdminDesignAction.java file. The vulnerability is exploited by manipulating the content argument, which leads to arbitrary code execution on the server.
Exploitation of this vulnerability allows for arbitrary code execution on the server where Fess is running.
To reproduce this vulnerability, upload a malicious JSP file through the Admin Design Action. Once the file is uploaded, access it via the web application and append a command parameter to execute arbitrary commands on the server. The output will be displayed at the bottom of the page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.