Security Advisory

CVE-2018-19146

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-06-17 19:53:48
Last updated 2024-08-05 11:30:04
Assigner mitre
State PUBLISHED

Description

Concrete5 8.4.3 has XSS because config/concrete.php allows uploads (by administrators) of SVG files that may contain HTML data with a SCRIPT element.