CVE-2019-17536: Malicious File Upload
Published Oct 13, 2019
·Updated
Gila CMS through 1.11.4 allows Unrestricted Upload of a File with a Dangerous Type via the moveAction function in core/controllers/fm.php. The attacker needs to use admin/mediaupload and fm/move.
Affected Software
1 affected component
GilaCMS Gila Cms<=1.11.4
Event History
Oct 13, 2019
CVE Published
via MITRE·05:52 PM
Data Sourced
via MITRE·05:52 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID for Gila CMS?
The vulnerability ID for Gila CMS is CVE-2019-17536.
2
What is the severity of CVE-2019-17536?
The severity of CVE-2019-17536 is critical (4.9).
3
How does CVE-2019-17536 allow unrestricted file upload?
CVE-2019-17536 allows unrestricted file upload through the moveAction function in core/controllers/fm.php.
4
What is the affected software version of CVE-2019-17536?
The affected software version of CVE-2019-17536 is Gila CMS 1.11.4.
5
How can an attacker exploit CVE-2019-17536?
An attacker can exploit CVE-2019-17536 by using admin/media_upload and fm/move.