VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 100 of 216
  • CVE-2021-37372HigOct 26, 2021
    risk 0.57cvss 8.8epss 0.03

    Online Student Admission System 1.0 is affected by an insecure file upload vulnerability. A low privileged user can upload malicious PHP files by updating their profile image to gain remote code execution.

  • CVE-2020-23043HigOct 22, 2021
    risk 0.57cvss 8.8epss 0.02

    Tran Tu Air Sender v1.0.2 was discovered to contain an arbitrary file upload vulnerability in the upload module. This vulnerability allows attackers to execute arbitrary code via a crafted file.

  • CVE-2021-41745CriOct 22, 2021
    risk 0.57cvss 9.8epss 0.01

    ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions.

  • CVE-2021-38346HigOct 14, 2021
    risk 0.57cvss 8.8epss 0.02

    The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a location of their choice using the brizy_create_block_screenshot AJAX action. The file would be named using the id parameter, which could be prepended with "../" to…

  • CVE-2021-39317HigOct 11, 2021
    risk 0.57cvss 8.8epss 0.02

    A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the…

  • CVE-2021-41919HigOct 8, 2021
    risk 0.57cvss 8.8epss 0.02

    webTareas version 2.4 and earlier allows an authenticated user to arbitrarily upload potentially dangerous files without restrictions. This is working by adding or replacing a personal profile picture. The affected endpoint is /includes/upload.php on the HTTP POST data. This…

  • CVE-2021-37741HigSep 21, 2021
    risk 0.57cvss 8.8epss 0.03

    ManageEngine ADManager Plus before 7111 has Pre-authentication RCE vulnerabilities.

  • CVE-2020-21322CriSep 15, 2021
    risk 0.57cvss 9.8epss 0.02

    An arbitrary file upload vulnerability in Feehi CMS v2.0.8 and below allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2021-33698HigSep 15, 2021
    risk 0.57cvss 8.8epss 0.01

    SAP Business One, version - 10.0, allows an attacker with business authorization to upload any files (including script files) without the proper file format validation.

  • CVE-2020-20670HigSep 13, 2021
    risk 0.57cvss 8.8epss 0.02

    An arbitrary file upload vulnerability in /admin/media/upload of ZKEACMS V3.2.0 allows attackers to execute arbitrary code via a crafted HTML file.

  • CVE-2021-24620HigSep 13, 2021
    risk 0.57cvss 8.8epss 0.01

    The WordPress Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin through 2.2.5 does not check for the uploaded Downloadable Digital product file, allowing any file, such as PHP to be uploaded by an administrator. Furthermore, as there is no CSRF in place,…

  • CVE-2021-36440CriSep 8, 2021
    risk 0.57cvss 9.8epss 0.05

    Unrestricted File Upload in ShowDoc v2.9.5 allows remote attackers to execute arbitrary code via the 'file_url' parameter in the component AdminUpdateController.class.php'.

  • CVE-2021-29907HigAug 31, 2021
    risk 0.57cvss 8.8epss 0.01

    IBM OpenPages with Watson 8.1 and 8.2 could allow an authenticated user to upload a file that could execute arbitrary code on the system. IBM X-Force ID: 207633.

  • CVE-2021-39141HigAug 23, 2021
    risk 0.57cvss 8.5epss 0.16

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed…

  • CVE-2020-27461HigAug 20, 2021
    risk 0.57cvss 8.8epss 0.04

    A remote code execution vulnerability in SEOPanel 4.6.0 has been fixed for 4.7.0. This vulnerability allowed for remote code execution through an authenticated file upload via the Settings Panel>Import website function.

  • CVE-2021-38366HigAug 12, 2021
    risk 0.57cvss 8.8epss 0.03

    Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code execution by visiting an uploaded .aspx file at an admin/Packages URL.

  • CVE-2020-21976HigAug 11, 2021
    risk 0.57cvss 8.8epss 0.02

    An arbitrary file upload in the component of NewsOne CMS v1.1.0 allows attackers to webshell and execute arbitrary commands.

  • CVE-2021-37444HigJul 25, 2021
    risk 0.57cvss 8.8epss 0.02

    NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive. This can lead to code execution if a ZIP element's pathname is set to a Windows startup folder, a file for the inbuilt Out-Going Message function, or a file…

  • CVE-2021-34619HigJul 21, 2021
    risk 0.57cvss 8.8epss 0.01

    The WooCommerce Stock Manager WordPress plugin is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Upload in versions up to, and including, 2.5.7 due to missing nonce and file validation in the /woocommerce-stock-manager/trunk/admin/views/import-export.php file.

  • CVE-2021-36121HigJul 13, 2021
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Echo ShareCare 8.15.5. The file-upload feature in Access/DownloadFeed_Mnt/FileUpload_Upd.cfm is susceptible to an unrestricted upload vulnerability via the name1 parameter, when processing remote input from an authenticated user, leading to the ability…