CVE-2018-10469: b3log Symphony
Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.
b3log Symphony (aka Sym) 2.6.0 allows remote attackers to upload and execute arbitrary JSP files via the name[] parameter to the /upload URI.
Affected products
- b3log Symphony: version 2.6.0 only
Published 2018-04-27. Last modified 2026-06-17.