Files
CVEs-PoC/2020/CVE-2020-26565.md
T
2024-05-25 21:48:12 +02:00

714 B

CVE-2020-26565

Description

ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter. This can be used to retrieve possibly sensitive serverInfo data.

POC

Reference

Github