VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,339)

page 183 of 217
  • CVE-2023-6635HigFeb 5, 2024
    risk 0.40cvss 7.2epss 0.02

    The EditorsKit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on the 'import_styles' function in versions up to, and including, 1.40.3. This makes it possible for authenticated attackers with administrator-level capabilities or…

  • CVE-2024-1069HigJan 31, 2024
    risk 0.40cvss 7.2epss 0.01

    The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'view_page' function in versions up to, and including, 1.3.2. This makes it possible for authenticated attackers with administrator-level capabilities…

  • CVE-2024-22550MedJan 26, 2024
    risk 0.40cvss 6.1epss 0.01

    An arbitrary file upload vulnerability in the component /alsdemo/ss/mediam.cgi of ShopSite v14.0 allows attackers to execute arbitrary code via uploading a crafted SVG file.

  • CVE-2023-6636HigJan 11, 2024
    risk 0.40cvss 7.2epss 0.01

    The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on the 'gspb_save_files' function in versions up to, and including, 7.6.2. This makes it possible for authenticated attackers…

  • CVE-2023-6558HigJan 11, 2024
    risk 0.40cvss 7.2epss 0.01

    The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'upload_import_file' function in versions up to, and including, 2.4.8. This makes it possible for authenticated attackers with…

  • CVE-2023-6826HigDec 15, 2023
    risk 0.40cvss 7.2epss 0.01

    The E2Pdf plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'import_action' function in versions up to, and including, 1.20.25. This makes it possible for authenticated attackers with a role that the administrator…

  • CVE-2023-6219HigNov 28, 2023
    risk 0.40cvss 7.2epss 0.01

    The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'bookingpress_process_upload' function in versions up to, and including, 1.0.76. This makes it possible for authenticated attackers with administrator-level…

  • CVE-2023-5860HigNov 2, 2023
    risk 0.40cvss 7.2epss 0.01

    The Icons Font Loader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload function in all versions up to, and including, 1.1.2. This makes it possible for authenticated attackers, with administrator-level access and…

  • CVE-2023-41564MedSep 8, 2023
    risk 0.40cvss 6.1epss 0.01

    An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a crafted .shtml file.

  • CVE-2023-3692HigJul 16, 2023
    risk 0.40cvss 7.2epss 0.01

    Unrestricted Upload of File with Dangerous Type in GitHub repository admidio/admidio prior to 4.2.10.

  • CVE-2023-34833MedJun 15, 2023
    risk 0.40cvss 6.1epss 0.01

    An arbitrary file upload vulnerability in the component /api/upload.php of ThinkAdmin v6 allows attackers to execute arbitrary code via a crafted file.

  • CVE-2022-25277HigApr 26, 2023
    risk 0.40cvss 7.2epss 0.01

    Drupal core sanitizes filenames with dangerous extensions upon upload (reference: SA-CORE-2020-012) and strips leading and trailing dots from filenames to prevent uploading server configuration files (reference: SA-CORE-2019-010). However, the protections for these two…

  • CVE-2021-41231HigJan 27, 2023
    risk 0.40cvss 7.2epss 0.01

    OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to upload files via DataFlow and to create products was able to execute arbitrary code via the convert profile. Versions 19.4.22 and 20.0.19 contain a patch for…

  • CVE-2022-34965HigJul 25, 2022
    risk 0.40cvss 7.2epss 0.02

    OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an arbitrary file upload vulnerability via the component /ossn/administrator/com_installer. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. Note: The project…

  • CVE-2022-1034HigMar 22, 2022
    risk 0.40cvss 7.2epss 0.01

    There is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in GitHub repository star7th/showdoc prior to 2.10.4.

  • CVE-2022-24749MedMar 14, 2022
    risk 0.40cvss 6.1epss 0.01

    Sylius is an open source eCommerce platform. In versions prior to 1.9.10, 1.10.11, and 1.11.2, it is possible to upload an SVG file containing cross-site scripting (XSS) code in the admin panel. In order to perform a XSS attack, the file itself has to be open in a new card or…

  • CVE-2021-42171HigMar 14, 2022
    risk 0.40cvss 7.2epss 0.03

    Zenario CMS 9.0.54156 is vulnerable to File Upload. The web server can be compromised by uploading and executing a web-shell which can run commands, browse system files, browse local resources, attack other servers, and exploit the local vulnerabilities, and so forth.

  • CVE-2021-24216HigMar 7, 2022
    risk 0.40cvss 7.2epss 0.02

    The All-in-One WP Migration WordPress plugin before 7.41 does not validate uploaded files' extension, which allows administrators to upload PHP files on their site, even on multisite installations.

  • CVE-2022-23043HigFeb 24, 2022
    risk 0.40cvss 7.2epss 0.01

    Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extension. Then an attacker can upload a malicious file, intercept the request and change the extension to '.phar' in order to run…

  • CVE-2022-0242HigJan 17, 2022
    risk 0.40cvss 7.2epss 0.01

    Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.