CVE-2019-17058: Footy Tipping Software

Critical severity, CVSS 9.1. EPSS: 1.9% chance of exploitation in the next 30 days.

Footy Tipping Software AFL Web Edition 2019 allows arbitrary file upload and resultant remote code execution because a whitelist can be bypassed by an Administrator who uploads a crafted upload.dat file.

Affected products

  • Footy Tipping Software: version 2019 only

Published 2019-11-18. Last modified 2026-06-17.