Security Advisory

CVE-2019-12150

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-05-24 15:39:26
Last updated 2024-08-04 23:10:30
Assigner mitre
State PUBLISHED

Description

Karamasoft UltimateEditor 1 does not ensure that an uploaded file is an image or document (neither file types nor extensions are restricted). The attacker must use the Attach icon to perform an upload. An uploaded file is accessible under the UltimateEditorInclude/UserFiles/ URI.