VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 123 of 216
  • CVE-2024-6823HigAug 13, 2024
    risk 0.50cvss 8.8epss 0.01

    The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation involving the mla-inline-edit-upload-scripts AJAX action in all versions up to, and including, 3.18. This makes it possible for authenticated attackers,…

  • CVE-2024-40645HigJul 31, 2024
    risk 0.50cvss 8.8epss 0.01

    FOG is a cloning/imaging/rescue suite/inventory management system. An improperly restricted file upload feature allows authenticated users to execute arbitrary code on the fogproject server. The Rebranding feature has a check on the client banner image requiring it to be 650…

  • CVE-2024-40400HigJul 19, 2024
    risk 0.50cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the image upload function of Automad v2.0.0 allows attackers to execute arbitrary code via a crafted file.

  • CVE-2024-3242HigJul 18, 2024
    risk 0.50cvss 8.8epss 0.01

    The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension validation in the validateImageContent function called via storeImages in all versions up to, and including, 2.4.43. This makes it possible for authenticated…

  • CVE-2024-31411HigJul 17, 2024
    risk 0.50cvss 8.8epss 0.01

    Unrestricted Upload of File with dangerous type vulnerability in Apache StreamPipes. Such a dangerous type might be an executable file that may lead to a remote code execution (RCE). The unrestricted upload is only possible for authenticated and authorized users. This issue…

  • CVE-2024-6319HigJul 4, 2024
    risk 0.50cvss 8.8epss 0.01

    The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload' function in all versions up to, and including, 2.3.10. This makes it possible for authenticated attackers, with contributor-level and above permissions,…

  • CVE-2024-6318HigJul 4, 2024
    risk 0.50cvss 8.8epss 0.01

    The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_img_file' function in all versions up to, and including, 2.3.10. This makes it possible for authenticated attackers, with contributor-level and above…

  • CVE-2024-2381HigJun 19, 2024
    risk 0.50cvss 8.8epss 0.01

    The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_save_image function in all versions up to, and including, 3.3.5. This makes it possible for authenticated attackers, with…

  • CVE-2024-4397HigMay 14, 2024
    risk 0.50cvss 8.8epss 0.01

    The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_post_materials' function in versions up to, and including, 4.2.6.5. This makes it possible for authenticated attackers, with…

  • CVE-2024-29891HigMar 27, 2024
    risk 0.50cvss 8.7epss 0.01

    ZITADEL users can upload their own avatar image and various image types are allowed. Due to a missing check, an attacker could upload HTML and pretend it is an image to gain access to the victim's account in certain scenarios. A possible victim would need to directly open the…

  • CVE-2024-27923HigMar 21, 2024
    risk 0.50cvss 8.8epss 0.01

    Grav is a content management system (CMS). Prior to version 1.7.43, users who may write a page may use the `frontmatter` feature due to insufficient permission validation and inadequate file name validation. This may lead to remote code execution. Version 1.7.43 fixes this issue.

  • CVE-2024-1311HigMar 13, 2024
    risk 0.50cvss 8.8epss 0.01

    The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeImages function in all versions up to, and including, 2.4.40. This makes it possible for authenticated attackers, with contributor access or…

  • CVE-2024-27733HigMar 7, 2024
    risk 0.50cvss 7.7epss 0.00

    File Upload vulnerability in Byzro Network Smart s42 Management Platform v.S42 allows a local attacker to execute arbitrary code via the useratte/userattestation.php component.

  • CVE-2023-6976HigDec 20, 2023
    risk 0.50cvss 8.8epss 0.01

    This vulnerability is capable of writing arbitrary files into arbitrary locations on the remote filesystem in the context of the server process.

  • CVE-2023-48217HigNov 14, 2023
    risk 0.50cvss 8.8epss 0.01

    Statamic is a flat-first, Laravel + Git powered CMS designed for building websites. In affected versions certain additional PHP files crafted to look like images may be uploaded regardless of mime type validation rules. This affects front-end forms using the "Forms" feature, and…

  • CVE-2023-47621HigNov 13, 2023
    risk 0.50cvss 8.8epss 0.01

    Guest Entries is a php library which allows users to create, update & delete entries from the front-end of a site. In affected versions the file uploads feature did not prevent the upload of PHP files. This may lead to code execution on the server by authenticated users. This…

  • CVE-2023-42462HigSep 27, 2023
    risk 0.50cvss 7.7epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. The document upload process can be diverted to delete some files. Users are advised to…

  • CVE-2020-20969HigJun 20, 2023
    risk 0.50cvss 7.2epss 0.06

    File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.

  • CVE-2023-2523HigMay 4, 2023
    risk 0.50cvss 7.3epss 0.33

    A vulnerability was found in Weaver E-Office 9.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file App/Ajax/ajax.php?action=mobile_upload_save. The manipulation of the argument upload_quwan leads to unrestricted upload. The attack…

  • CVE-2023-1313HigMar 10, 2023
    risk 0.50cvss 8.8epss 0.01

    Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit prior to 2.4.1.