ZeroHour

CVE-2019-12150

PoC
CVSS 3.0
9.8 critical
EPSS
2%p76
Published
()
Modified
Description

Karamasoft UltimateEditor 1 does not ensure that an uploaded file is an image or document (neither file types nor extensions are restricted). The attacker must use the Attach icon to perform an upload. An uploaded file is accessible under the UltimateEditorInclude/UserFiles/ URI.

Vendors
karamasoft
Products
ultimateeditor
Weakness
CWE-434
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.