CVE-2019-12185 | Elabftw 1.8.5 File Upload EntityController.php POST Request command injection (EDB-46869)
A vulnerability was found in Elabftw 1.8.5. It has been classified as critical. This vulnerability affects unknown code of the file /app/controllers/EntityController.php of the component File Upload. This manipulation as part of POST Request causes command injection.
The identification of this vulnerability is CVE-2019-12185. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.