CVE-2019-6503: Chatopera Cosin

Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.

There is a deserialization vulnerability in Chatopera cosin v3.10.0. An attacker can execute commands during server-side deserialization by uploading maliciously constructed files. This is related to the TemplateController.java impsave method and the MainUtils toObject method.

Affected products

Published 2019-01-22. Last modified 2026-06-17.