CVE-2019-19493: Malicious File Upload
Published Dec 2, 2019
·Updated
Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS.
Affected Software
2 affected components
Kentico Kentico>=9.0<12.0.50
Kentico Xperience>=9.0<12.0.50
Remediation
Patch Available
Event History
Dec 2, 2019
CVE Published
via MITRE·02:30 AM
Data Sourced
via MITRE·02:30 AM
Description
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-19493?
CVE-2019-19493 is considered a high severity vulnerability due to its potential to lead to Cross-Site Scripting (XSS) attacks.
2
How do I fix CVE-2019-19493?
To fix CVE-2019-19493, upgrade Kentico to version 12.0.50 or later.
3
What versions of Kentico are affected by CVE-2019-19493?
CVE-2019-19493 affects Kentico versions from 9.0 up to, but not including, 12.0.50.
4
What type of vulnerability is CVE-2019-19493?
CVE-2019-19493 is a Cross-Site Scripting (XSS) vulnerability caused by inconsistent Content-Type headers in file uploads.
5
Can CVE-2019-19493 lead to data breaches?
Yes, CVE-2019-19493 can potentially lead to data breaches through XSS attacks if successfully exploited.