Sploitus

CVE-2018-19420

1 known exploit for CVE-2018-19420

In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but there are several alternative cases in which HTML can be executed, such as a file with no extension or an unrecognized extension (e.g., the test or test.asdf filename), because of admin/upload-uploadify.php, and validate_safe_file in admin/inc/security_functions.php.

Affected products
Getsimple Cms
Get-simple Getsimple Cms
= 3.3.15
Fix
Available
CVSS 2.0
4.0 MEDIUM
CVSS 3.1
3.8 LOW
EPSS
0.8% (54th percentile)
Weakness
CWE-434
NVD status
Modified
Published
2018-11-21
CVE-2018-19420 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2018-19420

Proof-of-concept code and exploit modules indexed by Sploitus