VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,339)

page 186 of 217
  • CVE-2024-44220MedDec 12, 2024
    risk 0.36cvss 5.5epss 0.01

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. Parsing a maliciously crafted video file may lead to unexpected system termination.

  • CVE-2024-25020MedDec 3, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to malicious file upload by allowing unrestricted filetype attachments in the Journal entry page. Attackers can make use of this weakness and upload malicious executable files into the system and can be sent to…

  • CVE-2024-25019MedDec 3, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the type of file uploaded to Journal entry attachments. Attackers can make use of this weakness and upload malicious executable files into the system that can be sent to…

  • CVE-2024-27311MedJul 17, 2024
    risk 0.36cvss 5.5epss 0.01

    Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to directory traversal vulnerability which allows the user to upload new files to the server folder.

  • CVE-2024-35593MedMay 24, 2024
    risk 0.36cvss 5.5epss 0.00

    An arbitrary file upload vulnerability in the File preview function of Raingad IM v4.1.4 allows attackers to execute arbitrary code via uploading a crafted PDF file.

  • CVE-2024-3488MedMay 15, 2024
    risk 0.36cvss 5.6epss 0.00

    File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a file without authentication.

  • CVE-2024-29272MedMar 22, 2024
    risk 0.36cvss 6.5epss 0.09

    Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and obtain sensitive information via the sanitizeFileName parameter in save.php.

  • CVE-2023-45599MedMar 5, 2024
    risk 0.36cvss 5.5epss 0.00

    A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality of the web application allows a remote authenticated attacker to upload any arbitrary type of file into the device. This issue affects: AiLux imx6…

  • CVE-2024-0699MedFeb 5, 2024
    risk 0.36cvss 6.6epss 0.01

    The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'add_image_from_url' function in all versions up to, and including, 2.1.4. This makes it possible for…

  • CVE-2024-0505MedJan 13, 2024
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in ZhongFuCheng3y Austin 1.0 and classified as critical. This issue affects the function getFile of the file com/java3y/austin/web/controller/MaterialController.java of the component Upload Material Menu. The manipulation leads to unrestricted upload.…

  • CVE-2023-7054MedDec 22, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /user/add-notes.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit…

  • CVE-2023-6902MedDec 17, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability has been found in codelyfe Stupid Simple CMS up to 1.2.4 and classified as critical. This vulnerability affects unknown code of the file /file-manager/upload.php. The manipulation of the argument file leads to unrestricted upload. The exploit has been disclosed…

  • CVE-2023-6794MedDec 13, 2023
    risk 0.36cvss 5.5epss 0.01

    An arbitrary file upload vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.

  • CVE-2023-6449MedDec 1, 2023
    risk 0.36cvss 6.6epss 0.02

    The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'validate' function and insufficient blocklisting on the 'wpcf7_antiscript_file_name' function in versions up to, and including, 5.8.3. This makes it…

  • CVE-2023-6133MedNov 15, 2023
    risk 0.36cvss 6.6epss 0.01

    The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient blacklisting on the 'forminator_allowed_mime_types' function in versions up to, and including, 1.27.0. This makes it possible for authenticated attackers with administrator-level…

  • CVE-2023-31428MedAug 2, 2023
    risk 0.36cvss 5.5epss 0.00

    Brocade Fabric OS before Brocade Fabric OS v9.1.1c, v9.2.0 contains a vulnerability in the command line that could allow a local user to dump files under user's home directory using grep.

  • CVE-2023-3804MedJul 21, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability classified as problematic was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This vulnerability affects unknown code of the file /Service/FileHandler.ashx. The manipulation of the argument userFile leads to unrestricted upload. The…

  • CVE-2023-3802MedJul 21, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /Controller/Ajaxfileupload.ashx. The manipulation of the argument file leads to…

  • CVE-2023-3798MedJul 20, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0 and classified as critical. This vulnerability affects unknown code of the file /App_Resource/UEditor/server/upload.aspx. The manipulation of the argument file leads to unrestricted…

  • CVE-2023-3797MedJul 20, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability, which was classified as critical, was found in Gen Technology Four Mountain Torrent Disaster Prevention and Control of Monitoring and Early Warning System up to 20230712. This affects an unknown part of the file /Duty/AjaxHandle/UploadFloodPlanFileUpdate.ashx.…