ZeroHour

CVE-2019-13187

PoC
CVSS 3.0
9.8 critical
EPSS
2%p78
Published
()
Modified
Description

The Rich Text Formatter (Redactor) extension through v1.1.1 for Symphony CMS has an Unauthenticated arbitrary file upload vulnerability in content.fileupload.php and content.imageupload.php.

Vendors
symphonyextensions
Products
rich text formatter
Weakness
CWE-434
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.