Junglewise Threat Intelligence

CVE-2026-19852: CyberTutor NewSiteServer arbitrary file upload

CVE-2026-19852 · Severity: medium · CVSS 6.1 · Published 2026-08-24

Executive brief

NewSiteServer (NSS) is a campus website management system developed by CyberTutor. The product contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files, including HTML files that can perform cross-site scripting attacks. Exploitation could lead to defacement, data theft, or compromise of student and staff accounts through injected malicious content.

Technical details

NewSiteServer (NSS) is vulnerable to arbitrary file upload due to insufficient input validation or access controls on file upload endpoints. Unauthenticated remote attackers can upload arbitrary files, including HTML documents, without authentication. An attacker can leverage this to upload malicious HTML files that execute JavaScript in the context of the victim's browser (XSS-like behavior), potentially stealing session tokens, credentials, or performing actions on behalf of legitimate users. No patch status is currently documented; vendors should be contacted for remediation guidance.

Affected products

  • CyberTutor NewSiteServer (NSS) <UNKNOWN>

Timeline

  • 2026-08-24: disclosed
  • 2026-08-24: advisory: TVN-202608002 published by Taiwan CERT

References