CVE-2018-19600: XSS
Published Jan 3, 2019
·Updated
Rhymix CMS 1.9.8.1 allows XSS via an index.php?module=admin&act=dispModuleAdminFileBox SVG upload.
Affected Software
1 affected component
Rhymix Rhymix=1.9.8.1
Remediation
Patch Available
Event History
Jan 3, 2019
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19600?
CVE-2018-19600 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS).
2
How do I fix CVE-2018-19600?
To fix CVE-2018-19600, it's recommended to update to a patched version of Rhymix CMS that addresses the XSS vulnerability.
3
What types of attacks does CVE-2018-19600 allow?
CVE-2018-19600 allows attackers to execute malicious scripts via SVG uploads in the Rhymix CMS, leading to potential XSS attacks.
4
Who is affected by CVE-2018-19600?
CVE-2018-19600 affects users of Rhymix CMS version 1.9.8.1 who utilize the admin file upload functionality.
5
Can CVE-2018-19600 be exploited without authentication?
Yes, CVE-2018-19600 can be exploited without proper authentication, making it a risk for public-facing installations.