First published: Mon Dec 31 2018(Updated: )
CuppaCMS has XSS via an SVG document uploaded to the administrator/#/component/table_manager/view/cu_views URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tina Tinacms |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19918 has been classified with a moderate severity due to its potential for cross-site scripting attacks.
To fix CVE-2018-19918, it is recommended to sanitize and validate SVG files before allowing uploads within CuppaCMS.
CVE-2018-19918 affects all versions of CuppaCMS due to improper handling of SVG uploads.
CVE-2018-19918 is a cross-site scripting (XSS) vulnerability which could allow attackers to execute scripts in the context of an affected user's session.
Yes, if exploited, CVE-2018-19918 can lead to data theft or compromise by allowing attackers to run malicious scripts in the user's browser.