PT-2019-12662 · Karamasoft · Karamasoft Ultimateeditor

Arvin Christopher Moreno

·

Published

2019-05-24

·

Updated

2019-05-30

·

CVE-2019-12150

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Karamasoft UltimateEditor version 1
Description The issue allows an attacker to upload files without restrictions on file types or extensions. The upload can be performed using the Attach icon. Once uploaded, the files are accessible under the UltimateEditorInclude/UserFiles/ URI.
Recommendations For Karamasoft UltimateEditor version 1, restrict access to the Attach icon to prevent unauthorized file uploads, and consider implementing file type and extension restrictions to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-12150

Affected Products

Karamasoft Ultimateeditor