CVE-2019-15503: Altavoz Prontuscms

Critical severity, CVSS 9.8. EPSS: 2.4% chance of exploitation in the next 30 days.

cgi-cpn/xcoding/prontus_videocut.cgi in AltaVoz Prontus (aka ProntusCMS) through 12.0.3.0 has "Improper Neutralization of Special Elements used in an OS Command," allowing attackers to execute OS commands via an HTTP GET parameter.

Affected products

  • Altavoz Prontuscms: up to and including 12.0.3.0

Published 2019-08-26. Last modified 2026-06-17.