First published: Wed Nov 21 2018(Updated: )
In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but Internet Explorer render HTML elements in a .eml file, because of admin/upload-uploadify.php, and validate_safe_file in admin/inc/security_functions.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Get-simple Getsimple Cms | =3.3.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-19421 is medium.
The affected software for CVE-2018-19421 is GetSimpleCMS version 3.3.15.
CVE-2018-19421 allows Internet Explorer to render HTML elements in a .eml file, bypassing the block on .html uploads in GetSimpleCMS 3.3.15.
Yes, a fix for CVE-2018-19421 is available. It is recommended to update GetSimpleCMS to a version that includes the fix.
You can find more information about CVE-2018-19421 at the following link: https://github.com/GetSimpleCMS/GetSimpleCMS/issues/1301