CVE-2018-19601: SSRF
Published Jan 3, 2019
·Updated
Rhymix CMS 1.9.8.1 allows SSRF via an index.php?module=admin&act=dispModuleAdminFileBox SVG upload.
Affected Software
1 affected component
Rhymix Rhymix=1.9.8.1
Remediation
Patch Available
Event History
Jan 3, 2019
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19601?
CVE-2018-19601 has a medium severity rating due to its potential to allow Server-Side Request Forgery (SSRF).
2
How do I fix CVE-2018-19601?
To fix CVE-2018-19601, upgrade Rhymix CMS to version 1.9.8.2 or later, which addresses the SSRF vulnerability.
3
What systems are impacted by CVE-2018-19601?
CVE-2018-19601 affects Rhymix CMS version 1.9.8.1 specifically.
4
What exploitation methods are associated with CVE-2018-19601?
CVE-2018-19601 can be exploited through crafted SVG file uploads in the admin module.
5
What criteria are used to identify CVE-2018-19601?
CVE-2018-19601 is identified by the presence of a vulnerability in configuration that allows unauthorized SSRF access.