CVE-2018-19421: Malicious File Upload
Published Nov 21, 2018
·Updated
In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but Internet Explorer render HTML elements in a .eml file, because of admin/upload-uploadify.php, and validatesafefile in admin/inc/securityfunctions.php.
Affected Software
1 affected component
Get-simple Getsimple Cms=3.3.15
Event History
Nov 21, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19421?
The severity of CVE-2018-19421 is medium.
2
What is the affected software for CVE-2018-19421?
The affected software for CVE-2018-19421 is GetSimpleCMS version 3.3.15.
3
How does CVE-2018-19421 impact GetSimpleCMS?
CVE-2018-19421 allows Internet Explorer to render HTML elements in a .eml file, bypassing the block on .html uploads in GetSimpleCMS 3.3.15.
4
Is there a fix for CVE-2018-19421?
Yes, a fix for CVE-2018-19421 is available. It is recommended to update GetSimpleCMS to a version that includes the fix.
5
Where can I find more information about CVE-2018-19421?
You can find more information about CVE-2018-19421 at the following link: https://github.com/GetSimpleCMS/GetSimpleCMS/issues/1301