Medium severity4.8NVD Advisory· Published Jun 17, 2019· Updated Jun 17, 2026
CVE-2018-19146
CVE-2018-19146
Description
Concrete5 8.4.3 has XSS because config/concrete.php allows uploads (by administrators) of SVG files that may contain HTML data with a SCRIPT element.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Concrete5/Concrete5description
Patches
Vulnerability mechanics
References
4- hackerone.com/reports/437863nvdExploitIssue TrackingThird Party Advisory
- hackerone.com/concrete5nvdThird Party Advisory
- www.concrete5.orgnvdVendor Advisory
- www.w3.org/TR/SVG2/intro.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.