VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,434)

page 116 of 222
  • CVE-2024-46482HigOct 22, 2024
    risk 0.53cvss 8.2epss 0.00

    An arbitrary file upload vulnerability in the Ticket Generation function of Ladybird Web Solution Faveo-Helpdesk v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .html or .svg file.

  • CVE-2024-42991HigSep 3, 2024
    risk 0.53cvss 8.1epss 0.01

    MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.

  • CVE-2024-24550HigJun 24, 2024
    risk 0.53cvss 8.1epss 0.01

    A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File API which leads to arbitrary code execution on the server. This vulnerability arises from improper handling of file uploads,…

  • CVE-2023-46694HigMay 28, 2024
    risk 0.53cvss 8.1epss 0.01

    Vtenext 21.02 allows an authenticated attacker to upload arbitrary files, potentially enabling them to execute remote commands. This flaw exists due to the application's failure to enforce proper authentication controls when accessing the Ckeditor file manager functionality.

  • CVE-2024-33556HigMay 17, 2024
    risk 0.53cvss 8.2epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.8.

  • CVE-2024-32256HigApr 16, 2024
    risk 0.53cvss 8.1epss 0.01

    Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via /tms/admin/change-image.php. When updating a current package, there are no checks for what types of files are uploaded from the image.

  • CVE-2024-1531HigMar 27, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could print random memory content in the RTU500 system log, if an authorized user uploads a specially crafted stb-language file.

  • CVE-2023-6220HigJan 11, 2024
    risk 0.53cvss 8.1epss 0.01

    The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'piotnetforms_ajax_form_builder' function in versions up to, and including, 1.0.28. This makes it possible for unauthenticated attackers to upload…

  • CVE-2024-0352HigJan 9, 2024
    risk 0.53cvss 7.3epss 0.73

    A vulnerability classified as critical was found in Likeshop up to 2.5.7.20210311. This vulnerability affects the function FileServer::userFormImage of the file server/application/api/controller/File.php of the component HTTP POST Request Handler. The manipulation of the…

  • CVE-2023-45724HigJan 3, 2024
    risk 0.53cvss 8.2epss 0.01

    HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the upload of a certain file without requiring user authentication.

  • CVE-2023-5822HigNov 22, 2023
    risk 0.53cvss 8.1epss 0.02

    The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'dnd_upload_cf7_upload' function in versions up to, and including, 1.3.7.3. This makes it possible for…

  • CVE-2023-5524HigOct 20, 2023
    risk 0.53cvss 8.2epss 0.00

    Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution via specific file types

  • CVE-2023-43696HigOct 9, 2023
    risk 0.53cvss 8.2epss 0.01

    Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous access to the FTP server.

  • CVE-2023-43497HigSep 20, 2023
    risk 0.53cvss 8.1epss 0.01

    In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using the Stapler web framework creates temporary files in the default system temporary directory with the default permissions for newly created files, potentially allowing attackers with access to…

  • CVE-2023-3032HigJun 2, 2023
    risk 0.53cvss 8.1epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Mobatime web application (Documentary proof upload modules) allows a malicious user to Upload a Web Shell to a Web Server.This issue affects Mobatime web application: through 06.7.22.

  • CVE-2023-32686HigMay 27, 2023
    risk 0.53cvss 8.1epss 0.00

    Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to upload attachments to test plans, test cases, etc. Earlier versions of Kiwi TCMS had introduced upload validators in order to prevent potentially dangerous files…

  • CVE-2023-26098HigApr 25, 2023
    risk 0.53cvss 8.2epss 0.00

    An issue was discovered in the Open Document feature in Telindus Apsal 3.14.2022.235 b. An attacker may upload a crafted file to execute arbitrary code.

  • CVE-2023-30613HigApr 24, 2023
    risk 0.53cvss 8.1epss 0.01

    Kiwi TCMS, an open source test management system, allows users to upload attachments to test plans, test cases, etc. In versions of Kiwi TCMS prior to 12.2, there is no control over what kinds of files can be uploaded. Thus, a malicious actor may upload an `.exe` file or a file…

  • CVE-2023-24317HigFeb 23, 2023
    risk 0.53cvss 8.1epss 0.01

    Judging Management System 1.0 was discovered to contain an arbitrary file upload vulnerability via the component edit_organizer.php.

  • CVE-2022-33859HigOct 28, 2022
    risk 0.53cvss 8.1epss 0.00

    A security vulnerability was discovered in the Eaton Foreseer EPMS software. Foreseer EPMS connects an operation’s vast array of devices to assist in the reduction of energy consumption and avoid unplanned downtime caused by the failures of critical systems. A threat actor may…