File Upload Vulnerability in LimeSurvey by LimeSurvey Project
CVE-2019-15640
7.5HIGH
What is CVE-2019-15640?
LimeSurvey versions prior to 3.17.10 are susceptible to a vulnerability where the application fails to properly validate the MIME type and file extension for uploaded images. This oversight can potentially allow an attacker to upload malicious files disguised as valid images, leading to security compromises. Users are encouraged to update to the latest version to mitigate risks associated with this vulnerability.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved