CVE-2018-16630: XSS
Published Dec 28, 2018
·Updated
Kirby v2.5.12 allows XSS by using the "site files" Add option to upload an SVG file.
Affected Software
2 affected components
composer/getkirby/kirby<=2.5.12
getkirby Kirby=2.5.12
Event History
Dec 28, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
May 14, 2022
Advisory Published
01:31 AM
Frequently Asked Questions
1
What is the severity of CVE-2018-16630?
CVE-2018-16630 is categorized with a moderate severity due to its potential for XSS attacks via SVG file uploads.
2
How do I fix CVE-2018-16630?
To resolve CVE-2018-16630, update to a newer version of Kirby that addresses this vulnerability.
3
What kind of attack can be executed using CVE-2018-16630?
CVE-2018-16630 allows an attacker to execute cross-site scripting (XSS) attacks through the upload of malicious SVG files.
4
Which version of Kirby is affected by CVE-2018-16630?
CVE-2018-16630 specifically affects Kirby version 2.5.12.
5
Is CVE-2018-16630 a web application vulnerability?
Yes, CVE-2018-16630 is a web application vulnerability that impacts file upload functionalities in Kirby.