CVE-2019-14315: XSS
Published Jul 28, 2019
·Updated
A cross-site scripting (XSS) vulnerability in upload.php in SunHater KCFinder 3.20-test1, 3.20-test2, 3.12, and earlier allows remote attackers to inject arbitrary web script or HTML via the CKEditorFuncNum parameter.
Affected Software
4 affected components
composer/sunhater/kcfinder<=3.20-test2
SunHater KCFinder<=3.12
SunHater KCFinder=3.20-test1
SunHater KCFinder=3.20-test2
Event History
Jul 28, 2019
CVE Published
via MITRE·12:23 AM
Data Sourced
via MITRE·12:23 AM
Description
May 24, 2022
Advisory Published
via GitHub·04:51 PM
Frequently Asked Questions
1
What is the severity of CVE-2019-14315?
CVE-2019-14315 is considered a high severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2019-14315?
To fix CVE-2019-14315, update KCFinder to the latest version that is not vulnerable, specifically versions beyond 3.20-test2.
3
What systems are affected by CVE-2019-14315?
CVE-2019-14315 affects KCFinder versions 3.20-test1, 3.20-test2, and 3.12 and earlier.
4
What type of vulnerability is CVE-2019-14315?
CVE-2019-14315 is classified as a cross-site scripting (XSS) vulnerability.
5
Can CVE-2019-14315 allow for remote exploitation?
Yes, CVE-2019-14315 allows remote attackers to inject arbitrary web scripts or HTML, leading to potential exploitation.