First published: Sun Oct 13 2019(Updated: )
Gila CMS through 1.11.4 allows Unrestricted Upload of a File with a Dangerous Type via the moveAction function in core/controllers/fm.php. The attacker needs to use admin/media_upload and fm/move.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tina Tinacms | <=1.11.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for Gila CMS is CVE-2019-17536.
The severity of CVE-2019-17536 is critical (4.9).
CVE-2019-17536 allows unrestricted file upload through the moveAction function in core/controllers/fm.php.
The affected software version of CVE-2019-17536 is Gila CMS 1.11.4.
An attacker can exploit CVE-2019-17536 by using admin/media_upload and fm/move.