VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 130 of 216
  • CVE-2024-6110HigJun 18, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in itsourcecode Magbanua Beach Resort Online Reservation System up to 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file controller.php. The manipulation of the argument image leads to unrestricted…

  • CVE-2024-6084HigJun 18, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in itsourcecode Pool of Bethesda Online Reservation System up to 1.0 and classified as critical. Affected by this vulnerability is the function uploadImage of the file /admin/mod_room/controller.php?action=add. The manipulation of the argument…

  • CVE-2024-5745HigJun 7, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/modules/product/controller.php?action=add. The manipulation of the argument image leads to unrestricted upload. It…

  • CVE-2024-5377HigMay 26, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Vehicle Management System 1.0. It has been classified as critical. This affects an unknown part of the file /newvehicle.php. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack…

  • CVE-2024-5047HigMay 17, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Student Management System 1.0. Affected is an unknown function of the file /student/controller.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack…

  • CVE-2024-4966HigMay 16, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester SchoolWebTech 1.0. It has been classified as critical. Affected is an unknown function of the file /improve/home.php. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely.…

  • CVE-2024-4927HigMay 16, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /simple-online-bidding-system/admin/ajax.php?action=save_product. The manipulation leads to…

  • CVE-2024-4920HigMay 16, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file registerH.php. The manipulation of the argument ima leads to unrestricted upload. The attack may be initiated…

  • CVE-2024-4349HigApr 30, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in SourceCodester Pisay Online E-Learning System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /lesson/controller.php. The manipulation of the argument file leads to unrestricted upload. The…

  • CVE-2024-3437HigApr 8, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /Admin/add-admin.php of the component Avatar Handler. The manipulation of the argument avatar leads to unrestricted…

  • CVE-2024-2930HigMar 27, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file classes/Master.php?f=save_music. The manipulation leads to unrestricted upload. The attack can be launched…

  • CVE-2024-1116HigJan 31, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in openBI up to 1.0.8. It has been classified as critical. Affected is the function index of the file /application/plugins/controller/Upload.php. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit…

  • CVE-2024-1036HigJan 30, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in openBI up to 1.0.8 and classified as critical. This issue affects the function uploadIcon of the file /application/index/controller/Screen.php of the component Icon Handler. The manipulation leads to unrestricted upload. The attack may be initiated…

  • CVE-2024-1035HigJan 30, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in openBI up to 1.0.8 and classified as critical. This vulnerability affects the function uploadIcon of the file /application/index/controller/Icon.php. The manipulation of the argument image leads to unrestricted upload. The attack can be…

  • CVE-2024-1034HigJan 30, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in openBI up to 1.0.8. This affects the function uploadFile of the file /application/index/controller/File.php. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit…

  • CVE-2024-24399HigJan 25, 2024
    risk 0.48cvss 7.2epss 0.16

    An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code to the backend/languages/index.php languages area.

  • CVE-2024-0648HigJan 17, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in Yunyou CMS up to 2.2.6 and classified as critical. This vulnerability affects unknown code of the file /app/index/controller/Common.php. The manipulation of the argument templateFile leads to unrestricted upload. The attack can be initiated…

  • CVE-2024-20272HigJan 17, 2024
    risk 0.48cvss 7.3epss 0.02

    A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system and execute commands on the underlying operating system. This vulnerability is due to a lack of…

  • CVE-2023-46474HigJan 11, 2024
    risk 0.48cvss 7.2epss 0.21

    File Upload vulnerability PMB v.7.4.8 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted PHP file uploaded to the start_import.php file.

  • CVE-2022-45275HigDec 12, 2022
    risk 0.48cvss 7.2epss 0.15

    An arbitrary file upload vulnerability in /queuing/admin/ajax.php?action=save_settings of Dynamic Transaction Queuing System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.