CVE-2018-19453: Malicious File Upload
Published Apr 10, 2019
·Updated
Kentico CMS before 11.0.45 allows unrestricted upload of a file with a dangerous type.
Affected Software
2 affected components
Kentico Kentico CMS<11.0.45
Kentico Xperience<11.0.45
Event History
Apr 10, 2019
CVE Published
via MITRE·08:49 PM
Data Sourced
via MITRE·08:49 PM
Description
Data Sourced
via NVD·09:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-19453?
CVE-2018-19453 is classified as a high severity vulnerability due to the potential for unrestricted file uploads.
2
How do I fix CVE-2018-19453?
To fix CVE-2018-19453, upgrade Kentico CMS to version 11.0.45 or later.
3
What type of files can be uploaded due to CVE-2018-19453?
CVE-2018-19453 allows the upload of files with dangerous types, which can include executable scripts or malware.
4
What are the consequences of exploiting CVE-2018-19453?
Exploiting CVE-2018-19453 may lead to remote code execution and full server compromise.
5
Does CVE-2018-19453 affect all versions of Kentico CMS?
CVE-2018-19453 affects all versions of Kentico CMS before 11.0.45.