First published: Mon Aug 26 2019(Updated: )
Limesurvey before 3.17.10 does not validate both the MIME type and file extension of an image.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Limesurvey Limesurvey | <3.17.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-15640.
CVE-2019-15640 has a severity keyword of high and a severity value of 7.5.
CVE-2019-15640 affects Limesurvey versions up to and excluding 3.17.10.
CVE-2019-15640 exploits the lack of validation of both the MIME type and file extension of an image in Limesurvey before 3.17.10.
To fix CVE-2019-15640, you should update your Limesurvey installation to version 3.17.10 or later.