Arbitrary File Upload Vulnerability in NewSiteServer by CyberTutor
CVE-2026-19852

5.1MEDIUM

Key Information:

Vendor

Cybertutor

Vendor
CVE Published:
24 August 2026

What is CVE-2026-19852?

The NewSiteServer (NSS) platform developed by CyberTutor is susceptible to an Arbitrary File Upload vulnerability, which allows unauthenticated remote attackers to upload arbitrary files. This includes potentially malicious HTML files that could facilitate attacks resembling cross-site scripting. Such vulnerabilities pose a significant risk as they may enable unauthorized access or disrupt the functionality of web applications.

Affected Version(s)

NewSiteServer (NSS) all

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.