CVE-2018-19597: XSS
Published Dec 19, 2018
·Updated
CMS Made Simple 2.2.8 allows XSS via an uploaded SVG document, a related issue to CVE-2017-16798.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple=2.2.8
Event History
Dec 19, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19597?
CVE-2018-19597 is classified as a cross-site scripting (XSS) vulnerability, which can have moderate to high severity depending on the context of the deployment.
2
How do I fix CVE-2018-19597?
To fix CVE-2018-19597, users should upgrade to a patched version of CMS Made Simple that addresses this vulnerability.
3
What systems are affected by CVE-2018-19597?
CVE-2018-19597 specifically affects CMS Made Simple version 2.2.8.
4
What type of attack does CVE-2018-19597 enable?
CVE-2018-19597 enables cross-site scripting (XSS) attacks via the upload of malicious SVG documents.
5
Is user input vulnerable in CVE-2018-19597?
Yes, CVE-2018-19597 allows attackers to exploit user input through the upload function, leading to potential XSS attacks.