Lucene search

K
cvelistMitreCVELIST:CVE-2018-19146
HistoryJun 17, 2019 - 7:53 p.m.

CVE-2018-19146

2019-06-1719:53:48
mitre
www.cve.org

5.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.7%

Concrete5 8.4.3 has XSS because config/concrete.php allows uploads (by administrators) of SVG files that may contain HTML data with a SCRIPT element.

5.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.7%

Related for CVELIST:CVE-2018-19146