CVE-2019-15640: Input Validation
Published Aug 26, 2019
·Updated
Limesurvey before 3.17.10 does not validate both the MIME type and file extension of an image.
Affected Software
1 affected component
Limesurvey LimeSurvey<3.17.10
Remediation
Event History
Aug 26, 2019
CVE Published
via MITRE·04:51 PM
Data Sourced
via MITRE·04:51 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-15640.
2
What is the severity of CVE-2019-15640?
CVE-2019-15640 has a severity keyword of high and a severity value of 7.5.
3
How does CVE-2019-15640 affect Limesurvey?
CVE-2019-15640 affects Limesurvey versions up to and excluding 3.17.10.
4
What does CVE-2019-15640 exploit?
CVE-2019-15640 exploits the lack of validation of both the MIME type and file extension of an image in Limesurvey before 3.17.10.
5
How can I fix CVE-2019-15640?
To fix CVE-2019-15640, you should update your Limesurvey installation to version 3.17.10 or later.