CVE-2018-10469: b3log Symphony

Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.

b3log Symphony (aka Sym) 2.6.0 allows remote attackers to upload and execute arbitrary JSP files via the name[] parameter to the /upload URI.

Affected products

  • b3log Symphony: version 2.6.0 only

Published 2018-04-27. Last modified 2026-06-17.