First published: Wed Dec 19 2018(Updated: )
CMS Made Simple 2.2.8 allows XSS via an uploaded SVG document, a related issue to CVE-2017-16798.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CMS Made Simple | =2.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19597 is classified as a cross-site scripting (XSS) vulnerability, which can have moderate to high severity depending on the context of the deployment.
To fix CVE-2018-19597, users should upgrade to a patched version of CMS Made Simple that addresses this vulnerability.
CVE-2018-19597 specifically affects CMS Made Simple version 2.2.8.
CVE-2018-19597 enables cross-site scripting (XSS) attacks via the upload of malicious SVG documents.
Yes, CVE-2018-19597 allows attackers to exploit user input through the upload function, leading to potential XSS attacks.