CVE-2018-25002: Input Validation
Published Dec 31, 2020
·Updated
uploader.php in the KCFinder integration project through 2018-06-01 for Drupal mishandles validation, aka SA-CONTRIB-2018-024. NOTE: This project is not covered by Drupal's security advisory policy.
Affected Software
1 affected component
SunHater Kcfinder Drupal<=2018-06-01
Event History
Dec 31, 2020
CVE Published
via MITRE·11:27 PM
Data Sourced
via MITRE·11:27 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-25002?
CVE-2018-25002 is classified as a moderately severe vulnerability due to improper validation in the uploader.php file.
2
How do I fix CVE-2018-25002?
To fix CVE-2018-25002, update KCFinder to a version beyond 2018-06-01 that addresses this validation issue.
3
What software is affected by CVE-2018-25002?
CVE-2018-25002 affects KCFinder integration for Drupal versions up to and including 2018-06-01.
4
What kind of vulnerability is CVE-2018-25002?
CVE-2018-25002 is a validation error vulnerability within the KCFinder integration project for Drupal.
5
Is CVE-2018-25002 covered by Drupal's security advisory policy?
No, CVE-2018-25002 is specifically noted as not being covered by Drupal's security advisory policy.