CVE-2018-19556: Input Validation
Published Nov 26, 2018
·Updated
DISPUTED zbsystem/admin/index.php?act=UploadMng in Z-BlogPHP 1.5 mishandles file preview, leading to content spoofing. NOTE: the software maintainer disputes that this is a vulnerability.
Affected Software
1 affected component
ZblogCN Z-blogphp=1.5
Event History
Nov 26, 2018
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Disputed
07:29 AM
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-19556.
2
What is the title of this vulnerability?
The title of this vulnerability is 'zb_system/admin/index.php?act=UploadMng in Z-BlogPHP 1.5 mishandles file preview'.
3
What is the severity of CVE-2018-19556?
The severity of CVE-2018-19556 is medium with a score of 4.3.
4
How does CVE-2018-19556 affect Z-BlogPHP?
CVE-2018-19556 affects Z-BlogPHP version 1.5.
5
Is there a fix available for CVE-2018-19556?
Yes, there is a fix available. Please refer to the software maintainer's response on the GitHub issue for more information.