CVE-2018-19146
Concrete5 8.4.3 has XSS because config/concrete.php allows uploads (by administrators) of SVG files that may contain HTML data with a SCRIPT element.
- Affected products
- Concrete5
- Concretecms Concrete Cms
- = 8.4.3
- Fix
- Available
- CVSS 3.0
- 4.8 MEDIUM
- EPSS
- 1.0% (60th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2019-06-17
CVE-2018-19146 at NVD
1 known exploit for CVE-2018-19146
Proof-of-concept code and exploit modules indexed by Sploitus