High severity7.2NVD Advisory· Published Jun 12, 2020· Updated Jun 17, 2026
CVE-2019-15123
CVE-2019-15123
Description
The Branding Module in Viki Vera 4.9.1.26180 allows an authenticated user to change the logo on the website. An attacker could use this to upload a malicious .aspx file and gain Remote Code Execution on the site.
Affected products
2- Viki/Veradescription
Patches
Vulnerability mechanics
References
2- www.vikisolutions.com/products/Vera.htmlnvdProductVendor Advisory
- www.gosecure.net/blog/2020/06/11/vera-vulnerable-to-authenticated-remote-code-execution-cve-2019-15123/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.