CVE-2019-15862

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
26/09/2019
Last modified:
02/10/2019

Description

An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload files without any extension (even if the application was configured to accept files only with a defined set of extensions). This affects CKFinder for ASP, CKFinder for ASP.NET, CKFinder for ColdFusion, and CKFinder for PHP.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cksource:ckfinder:*:*:*:*:*:asp:*:* 2.6.3 (excluding)
cpe:2.3:a:cksource:ckfinder:*:*:*:*:*:asp.net:*:* 2.6.3 (excluding)
cpe:2.3:a:cksource:ckfinder:*:*:*:*:*:coldfusion:*:* 2.6.3 (excluding)
cpe:2.3:a:cksource:ckfinder:*:*:*:*:*:php:*:* 2.6.3 (excluding)