VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 138 of 216
  • CVE-2024-57408HigFeb 10, 2025
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file upload vulnerability in the component /comm/upload of cool-admin-java v1.0 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-57407HigFeb 10, 2025
    risk 0.47cvss 7.3epss 0.00

    An arbitrary file upload vulnerability in the component /userPicture of Timo v2.0.3 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-13723HigFeb 4, 2025
    risk 0.47cvss 7.2epss 0.01

    The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP.

  • CVE-2025-0460HigJan 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability, which was classified as critical, was found in Blog Botz for Journal Theme 1.0 on OpenCart. This affects an unknown part of the file /index.php?route=extension/module/blog_add. The manipulation of the argument image leads to unrestricted upload. It is possible…

  • CVE-2024-46210HigJan 10, 2025
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-9698HigDec 14, 2024
    risk 0.47cvss 7.2epss 0.02

    The Crafthemes Demo Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'process_uploaded_files' function in all versions up to, and including, 3.3. This makes it possible for authenticated attackers, with…

  • CVE-2024-47946HigDec 10, 2024
    risk 0.47cvss 7.2epss 0.01

    If the attacker has access to a valid Poweruser session, remote code execution is possible because specially crafted valid PNG files with injected PHP content can be uploaded as desktop backgrounds or lock screens. After the upload, the PHP script is available in the web root.…

  • CVE-2024-52769HigNov 20, 2024
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file upload vulnerability in the component /admin/friendlink_edit of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-51208HigNov 20, 2024
    risk 0.47cvss 7.2epss 0.00

    File Upload vulnerability in change-image.php in Anuj Kumar's Boat Booking System version 1.0 allows local attackers to upload a malicious PHP script via the Image Upload Mechanism parameter.

  • CVE-2024-51152HigNov 8, 2024
    risk 0.47cvss 7.2epss 0.01

    File Upload vulnerability in Laravel CMS v.1.4.7 and before allows a remote attacker to execute arbitrary code via the shell.php a component.

  • CVE-2024-48454HigOct 24, 2024
    risk 0.47cvss 7.2epss 0.01

    An issue in SourceCodester Purchase Order Management System v1.0 allows a remote attacker to execute arbitrary code via the /admin?page=user component

  • CVE-2024-45398HigSep 17, 2024
    risk 0.47cvss 8.3epss 0.01

    Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the server. Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to update are advised to configure their web…

  • CVE-2024-6311HigAug 28, 2024
    risk 0.47cvss 7.2epss 0.01

    The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'af2_add_font' function in all versions up to, and including, 3.7.3.2. This makes it possible for authenticated attackers, with administrator-level and…

  • CVE-2024-42523HigAug 23, 2024
    risk 0.47cvss 7.2epss 0.01

    publiccms V4.0.202302.e and before is vulnerable to Any File Upload via publiccms/admin/cmsTemplate/saveMetaData

  • CVE-2024-42767HigAug 22, 2024
    risk 0.47cvss 7.2epss 0.01

    Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php.

  • CVE-2024-40318HigJul 25, 2024
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-6828HigJul 23, 2024
    risk 0.47cvss 7.2epss 0.01

    The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization and capability checks on the Redux_Color_Scheme_Import function in versions 4.4.12 to 4.4.17. This makes it possible for unauthenticated attackers to upload…

  • CVE-2024-3123HigJul 1, 2024
    risk 0.47cvss 7.2epss 0.01

    CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this vulnerability to upload and run malicious file to execute system commands.

  • CVE-2024-31161HigJun 14, 2024
    risk 0.47cvss 7.2epss 0.01

    The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrative privilege can exploit this vulnerability to upload any file to any location. They may even upload malicious web page files to the website directory,…

  • CVE-2024-34110HigJun 13, 2024
    risk 0.47cvss 7.2epss 0.01

    Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution. A high-privilege attacker could exploit this vulnerability by uploading a…