CVE-2014-5468: Getrailo Railo
High severity, CVSS 8.8. EPSS: 52.6% chance of exploitation in the next 30 days.
A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cfm to specify a malicious PNG file, which could let a remote malicious user obtain sensitive information or execute arbitrary code.
Affected products
- Getrailo Railo: up to and including 4.2.1.000
Published 2020-02-07. Last modified 2026-06-17.