Karamasoft UltimateEditor 1 does not ensure that an uploaded file is an image or document (neither file types nor extensions are restricted). The attacker must use the Attach icon to perform an upload. An uploaded file is accessible under the UltimateEditorInclude/UserFiles/ URI.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/Gr4y21/My-CVE-IDs/blob/master/CVE-2019-12150/Karamasoft%20Arbitrary%20File%20Upload | Exploit Third Party Advisory | 
| https://www.karamasoft.com | Product Vendor Advisory | 
| https://github.com/Gr4y21/My-CVE-IDs/blob/master/CVE-2019-12150/Karamasoft%20Arbitrary%20File%20Upload | Exploit Third Party Advisory | 
| https://www.karamasoft.com | Product Vendor Advisory | 
Configurations
                    History
                    No history.
Information
                Published : 2019-05-24 16:29
Updated : 2024-11-21 04:22
NVD link : CVE-2019-12150
Mitre link : CVE-2019-12150
CVE.ORG link : CVE-2019-12150
JSON object : View
Products Affected
                karamasoft
- ultimateeditor
CWE
                
                    
                        
                        CWE-434
                        
            Unrestricted Upload of File with Dangerous Type
