CVE-2018-19146
EUVD-2018-1085817.06.2019, 20:15
Concrete5 8.4.3 has XSS because config/concrete.php allows uploads (by administrators) of SVG files that may contain HTML data with a SCRIPT element.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| concretecms | concrete_cms | 8.4.3 |
𝑥
= Vulnerable software versions
References