CVE-2019-15123

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
12/06/2020
Last modified:
23/06/2020

Description

The Branding Module in Viki Vera 4.9.1.26180 allows an authenticated user to change the logo on the website. An attacker could use this to upload a malicious .aspx file and gain Remote Code Execution on the site.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vikisolutions:vera:4.9.1.26180:*:*:*:*:*:*:*