CVE-2019-16126: XSS
Published Sep 9, 2019
·Updated
Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images.
Affected Software
1 affected component
getgrav Grav Cms<=1.6.15
Event History
Sep 9, 2019
CVE Published
via MITRE·01:01 AM
Data Sourced
via MITRE·01:01 AM
Description
Frequently Asked Questions
1
What is CVE-2019-16126?
CVE-2019-16126 is a vulnerability in Grav CMS that allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images.
2
How severe is CVE-2019-16126?
CVE-2019-16126 has a severity level of medium with a CVSS score of 6.1.
3
How does CVE-2019-16126 affect Grav CMS?
CVE-2019-16126 affects Grav CMS versions up to and including 1.6.15.
4
Is there a fix for CVE-2019-16126?
At the moment, there is no official fix available for CVE-2019-16126. It is recommended to update to the latest version of Grav CMS when a patch becomes available.
5
Where can I find more information about CVE-2019-16126?
More information about CVE-2019-16126 can be found in the GitHub issue: https://github.com/getgrav/grav/issues/2657