VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 163 of 216
  • CVE-2025-13815MedDec 1, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the file /file/pictures. This manipulation of the argument filedatas causes unrestricted upload. The attack may be initiated remotely. The exploit has been made…

  • CVE-2025-51736MedNov 28, 2025
    risk 0.41cvss 6.3epss 0.00

    File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0.

  • CVE-2025-13573MedNov 24, 2025
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in projectworlds can pass malicious payloads up to 1.0. This vulnerability affects unknown code of the file /add_book.php. The manipulation of the argument image results in unrestricted upload. The attack can be executed remotely. The exploit…

  • CVE-2025-13544MedNov 23, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is an unknown function of the file /customer_register.php. Executing manipulation can lead to unrestricted upload. It is possible to launch the attack remotely.…

  • CVE-2025-13249MedNov 16, 2025
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in Jiusi OA up to 20251102. This affects an unknown function of the file /OfficeServer?isAjaxDownloadTemplate=false of the component OfficeServer Interface. Such manipulation of the argument FileData leads to unrestricted upload. The…

  • CVE-2025-13238MedNov 16, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in Bdtask Flight Booking Software 4. Affected by this vulnerability is an unknown functionality of the file /agent/profile/edit of the component Edit Profile Page. This manipulation causes unrestricted upload. The attack may be initiated remotely.…

  • CVE-2025-13061MedNov 12, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in itsourcecode Online Voting System 1.0. This impacts an unknown function of the file /index.php?page=manage_voting. Performing manipulation results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public…

  • CVE-2025-59118HigNov 12, 2025
    risk 0.41cvss 7.3epss 0.02

    Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommended to upgrade to version 24.09.03, which fixes the issue.

  • CVE-2025-12862MedNov 7, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in projectworlds Online Notes Sharing Platform 1.0. Affected by this issue is some unknown functionality of the file /dashboard/userprofile.php. Such manipulation of the argument image leads to unrestricted upload. The attack may be performed from…

  • CVE-2025-12347MedOct 28, 2025
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in MaxSite CMS up to 109. This issue affects some unknown processing of the file application/maxsite/admin/plugins/editor_files/save-file-ajax.php. Executing manipulation of the argument file_path/content can lead to unrestricted upload. The attack can be…

  • CVE-2025-12346MedOct 28, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in MaxSite CMS up to 109. This vulnerability affects unknown code of the file application/maxsite/admin/plugins/auto_post/uploads-require-maxsite.php of the component HTTP Header Handler. Performing manipulation of the argument…

  • CVE-2025-12344MedOct 28, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in Yonyou U8 Cloud up to 5.1sp. The impacted element is an unknown function of the file /service/NCloudGatewayServlet of the component Request Header Handler. Such manipulation of the argument ts/sign leads to unrestricted upload. The attack may be…

  • CVE-2025-12268MedOct 27, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Impacted is an unknown function of the file /api/v1/courses/ of the component Course Thumbnail Handler. The manipulation of the argument thumbnail leads to unrestricted upload. It is…

  • CVE-2025-12223MedOct 27, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in Bdtask Flight Booking Software up to 3.1. This affects an unknown part of the file /b2c/package-information of the component Package Information Module. The manipulation results in unrestricted upload. The attack can be launched remotely. The…

  • CVE-2025-12222MedOct 27, 2025
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in Bdtask Flight Booking Software up to 3.1. Affected by this issue is some unknown functionality of the file /admin/transaction/deposit of the component Deposit Handler. The manipulation leads to unrestricted upload. The attack can be…

  • CVE-2025-11908MedOct 17, 2025
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The affected element is the function uploadFile of the file /FileDir.do?Action=Upload. Performing manipulation of the argument File results in unrestricted upload. The attack is possible…

  • CVE-2025-11436MedOct 8, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in JhumanJ OpnForm up to 1.9.3. Affected by this issue is some unknown functionality of the file /answer. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit is now public and may be used. The patch is…

  • CVE-2025-11426MedOct 8, 2025
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit_book.php. The manipulation of the argument image results in unrestricted upload. It is possible to launch the…

  • CVE-2025-11417MedOct 8, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in Campcodes Advanced Online Voting Management System 1.0. This vulnerability affects unknown code of the file /admin/voters_add.php. Executing manipulation of the argument photo can lead to unrestricted upload. The attack can be launched remotely.…

  • CVE-2025-11398MedOct 7, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in SourceCodester Hotel and Lodge Management System 1.0. The impacted element is an unknown function of the file /profile.php of the component Profile Page. Executing manipulation of the argument image can lead to unrestricted upload. The attack…