CVE-2018-19918: XSS
Published Dec 31, 2018
·Updated
CuppaCMS has XSS via an SVG document uploaded to the administrator/#/component/tablemanager/view/cuviews URI.
Affected Software
1 affected component
CuppaCMS CuppaCMS
Event History
Dec 31, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19918?
CVE-2018-19918 has been classified with a moderate severity due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2018-19918?
To fix CVE-2018-19918, it is recommended to sanitize and validate SVG files before allowing uploads within CuppaCMS.
3
What systems are affected by CVE-2018-19918?
CVE-2018-19918 affects all versions of CuppaCMS due to improper handling of SVG uploads.
4
What type of vulnerability is CVE-2018-19918?
CVE-2018-19918 is a cross-site scripting (XSS) vulnerability which could allow attackers to execute scripts in the context of an affected user's session.
5
Can CVE-2018-19918 lead to data theft or compromise?
Yes, if exploited, CVE-2018-19918 can lead to data theft or compromise by allowing attackers to run malicious scripts in the user's browser.