Description
Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.
Remediation
References
Related Vulnerabilities
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-11588)
Atlassian Jira Incorrect Behavior Order: Validate Before Canonicalize Vulnerability (CVE-2022-26137)
PHP Improper Input Validation Vulnerability (CVE-2016-4071)
PHP Other Vulnerability (CVE-2007-1884)
WordPress Plugin Bird Feeder Multiple Vulnerabilities (1.2.3)