VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 157 of 216
  • CVE-2024-34683MedJun 11, 2024
    risk 0.42cvss 6.5epss 0.00

    An authenticated attacker can upload malicious file to SAP Document Builder service. When the victim accesses this file, the attacker is allowed to access, modify, or make the related information unavailable in the victim’s browser.

  • CVE-2023-45188MedJun 9, 2024
    risk 0.42cvss 6.5epss 0.01

    IBM Engineering Lifecycle Optimization Publishing 7.0.2 and 7.03 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially crafted request, a remote attacker could exploit this vulnerability to upload a…

  • CVE-2024-1332MedMay 24, 2024
    risk 0.42cvss 6.4epss 0.00

    The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg file upload in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2023-39462MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.02

    Triangle MicroWorks SCADA Data Gateway Workspace Unrestricted Upload Vulnerability. This vulnerability allows remote attackers to upload arbitrary files on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this…

  • CVE-2024-29368MedApr 22, 2024
    risk 0.42cvss 6.5epss 0.01

    An arbitrary file upload vulnerability in the file handling module of moziloCMS v2.0 allows attackers to bypass extension restrictions via file renaming, potentially leading to unauthorized file execution or storage of malicious content.

  • CVE-2024-31210HigApr 4, 2024
    risk 0.42cvss 7.6epss 0.01

    WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted as a new plugin by an administrative user on the Plugins -> Add New -> Upload Plugin screen in WordPress. If FTP credentials are requested for…

  • CVE-2024-28520MedApr 4, 2024
    risk 0.42cvss 6.5epss 0.00

    File Upload vulnerability in Byzoro Networks Smart multi-service security gateway intelligent management platform version S210, allows an attacker to obtain sensitive information via the uploadfile.php component.

  • CVE-2024-28418MedMar 14, 2024
    risk 0.42cvss 6.5epss 0.00

    Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php

  • CVE-2024-24146MedFeb 29, 2024
    risk 0.42cvss 6.5epss 0.01

    A memory leak issue discovered in parseSWF_DEFINEBUTTON in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF file.

  • CVE-2022-45377MedDec 21, 2023
    risk 0.42cvss 6.5epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload for WooCommerce.This issue affects Drag and Drop Multiple File Upload for WooCommerce: from n/a through 1.0.8.

  • CVE-2023-6827HigDec 15, 2023
    risk 0.42cvss 7.5epss 0.01

    The Essential Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'ajaxUploadFonts' function in versions up to, and including, 4.3.5. This makes it possible for authenticated attackers with subscriber-level…

  • CVE-2023-5154MedSep 25, 2023
    risk 0.42cvss 6.3epss 0.15

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DAR-8000 up to 20151231 and classified as critical. This vulnerability affects unknown code of the file /sysmanage/changelogo.php. The manipulation of the argument file_upload leads to unrestricted upload.…

  • CVE-2023-24517MedAug 22, 2023
    risk 0.42cvss 6.4epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in the Pandora FMS File Manager component, allows an attacker to make make use of this issue ( unrestricted file upload ) to execute arbitrary system commands. This issue affects Pandora FMS v767 version and prior…

  • CVE-2023-28482MedAug 14, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Tigergraph Enterprise 3.7.0. A single TigerGraph instance can host multiple graphs that are accessed by multiple different users. The TigerGraph platform does not protect the confidentiality of any data uploaded to the remote server. In this scenario,…

  • CVE-2023-28480MedAug 14, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Tigergraph Enterprise 3.7.0. The TigerGraph platform allows users to define new User Defined Functions (UDFs) from C/C++ code. To support this functionality TigerGraph allows users to upload custom C/C++ code which is then compiled and installed into…

  • CVE-2023-32526MedJun 26, 2023
    risk 0.42cvss 6.5epss 0.02

    Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary files on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target…

  • CVE-2023-32525MedJun 26, 2023
    risk 0.42cvss 6.5epss 0.02

    Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary files on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target…

  • CVE-2023-34660MedJun 16, 2023
    risk 0.42cvss 6.5epss 0.01

    jjeecg-boot V3.5.0 has an unauthorized arbitrary file upload in /jeecg-boot/jmreport/upload interface.

  • CVE-2023-22504MedMay 25, 2023
    risk 0.42cvss 6.5epss 0.01

    Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.

  • CVE-2023-20073MedApr 5, 2023
    risk 0.42cvss 5.3epss 0.89

    A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to insufficient authorization…