CVE-2019-6503: Chatopera Cosin
Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.
There is a deserialization vulnerability in Chatopera cosin v3.10.0. An attacker can execute commands during server-side deserialization by uploading maliciously constructed files. This is related to the TemplateController.java impsave method and the MainUtils toObject method.
Affected products
- Chatopera Cosin: version 3.10.0 only
Published 2019-01-22. Last modified 2026-06-17.