The Branding Module in Viki Vera 4.9.1.26180 allows an authenticated user to change the logo on the website. An attacker could use this to upload a malicious .aspx file and gain Remote Code Execution on the site.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-6192 The Branding Module in Viki Vera 4.9.1.26180 allows an authenticated user to change the logo on the website. An attacker could use this to upload a malicious .aspx file and gain Remote Code Execution on the site.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T00:34:53.385Z

Reserved: 2019-08-16T00:00:00

Link: CVE-2019-15123

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-06-12T21:15:09.757

Modified: 2024-11-21T04:28:05.983

Link: CVE-2019-15123

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses