CVE-2018-19508: XSS
Published Dec 19, 2018
·Updated
CMSimple 4.7.5 has XSS via an admin's upload of an SVG file at a ?userfiles&subdir=userfiles/images/flags/ URI.
Affected Software
1 affected component
CmSimple CMSimple=4.7.5
Event History
Dec 19, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-19508.
2
What is the description of this vulnerability?
The description of this vulnerability is XSS (Cross-Site Scripting) via an admin's upload of an SVG file.
3
What is the severity of CVE-2018-19508?
The severity of CVE-2018-19508 is medium with a CVSSv3 score of 4.8.
4
How does this vulnerability occur?
This vulnerability occurs when an admin uploads an SVG file through the CMSimple application.
5
Is there any fix available for this vulnerability?
There is currently no known fix available for this vulnerability. It is recommended to upgrade to a patched version of CMSimple if available.