VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,339)

page 189 of 217
  • CVE-2023-44962MedOct 11, 2023
    risk 0.35cvss 5.3epss 0.01

    File Upload vulnerability in Koha Library Software 23.05.04 and before allows a remote attacker to read arbitrary files via the upload-cover-image.pl component.

  • CVE-2023-44763MedOct 10, 2023
    risk 0.35cvss 5.4epss 0.01

    Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cross-Site Scripting (XSS). NOTE: the vendor's position is that a customer is supposed to know that "pdf" should be excluded from the allowed file types, even…

  • CVE-2023-34845MedJun 16, 2023
    risk 0.35cvss 5.4epss 0.01

    Bludit v3.14.1 was discovered to contain an arbitrary file upload vulnerability in the component /admin/new-content. This vulnerability allows attackers to execute arbitrary web scripts or HTML via uploading a crafted SVG file. NOTE: the product's security model is that users…

  • CVE-2023-20134MedApr 5, 2023
    risk 0.35cvss 5.4epss 0.00

    Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack or upload arbitrary files as recordings. For more information about these vulnerabilities, see the Details…

  • CVE-2023-23851MedFeb 14, 2023
    risk 0.35cvss 5.4epss 0.00

    SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages) without the proper file format validation. If other users visit the uploaded malicious web page, the attacker may perform actions…

  • CVE-2021-36573MedDec 15, 2022
    risk 0.35cvss 5.4epss 0.00

    File Upload vulnerability in Feehi CMS thru 2.1.1 allows attackers to run arbitrary code via crafted image upload.

  • CVE-2022-0959MedMar 16, 2022
    risk 0.35cvss 6.5epss 0.01

    A malicious, but authorised and authenticated user can construct an HTTP request using their existing CSRF token and session cookie to manually upload files to any location that the operating system user account under which pgAdmin is running has permission to write.

  • CVE-2021-24960MedMar 7, 2022
    risk 0.35cvss 5.4epss 0.01

    The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allows users with a role as low as Contributor to configure the upload form in a way that allows uploading of SVG files, which could be then be used for Cross-Site…

  • CVE-2021-32594MedAug 4, 2021
    risk 0.35cvss 5.4epss 0.01

    An unrestricted file upload vulnerability in the web interface of FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier may allow a low-privileged user to potentially tamper with the underlying system's files via the upload of…

  • CVE-2021-29022MedMay 10, 2021
    risk 0.35cvss 5.3epss 0.01

    In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.

  • CVE-2020-6288MedSep 9, 2020
    risk 0.35cvss 5.3epss 0.01

    SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface) allows an attacker with edit document rights to upload any file (including script files) without proper file format validation leading to Unrestricted upload of file with dangerous type…

  • CVE-2020-7302MedAug 13, 2020
    risk 0.35cvss 5.4epss 0.01

    Unrestricted Upload of File with Dangerous Type in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to upload malicious files to the DLP case management section via lack of sanity checking.

  • CVE-2020-2730MedJan 15, 2020
    risk 0.35cvss 5.4epss 0.01

    Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: File Upload). Supported versions that are affected are 2.7.0.0, 2.7.0.1 and 2.8.0.0. Easily exploitable vulnerability allows low privileged…

  • CVE-2011-4907MedJan 15, 2020
    risk 0.35cvss 5.3epss 0.01

    Joomla! 1.5x through 1.5.12: Missing JEXEC Check

  • CVE-2019-6513MedMay 21, 2019
    risk 0.35cvss 5.4epss 0.02

    An issue was discovered in WSO2 API Manager 2.6.0. It is possible for a logged-in user to upload, as API documentation, any type of file by changing the extension to an allowed one.

  • CVE-2018-16821MedSep 21, 2018
    risk 0.35cvss 5.3epss 0.01

    SeaCMS 6.64 allows arbitrary directory listing via upload/admin/admin_template.php?path=../templets/../../ requests.

  • CVE-2011-4183MedJun 13, 2018
    risk 0.35cvss 6.5epss 0.01

    A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE open build service prior to 2.1.16.

  • CVE-2016-2914MedAug 8, 2016
    risk 0.35cvss 5.4epss 0.02

    Unrestricted file upload vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authenticated users to execute arbitrary code by specifying an unexpected file extension.

  • CVE-2024-14046MedAug 18, 2026
    risk 0.34cvss 6.3epss 0.00

    A security vulnerability has been detected in OpenBoxes up to 0.9.1. This issue affects the function DocumentController of the file grails-app/controllers/org/pih/warehouse/core/DocumentController.groovy of the component Document Upload Controller. The manipulation leads to…

  • CVE-2026-34027MedJun 15, 2026
    risk 0.34cvss epss 0.00

    The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains insufficient server-side file type validation in the /safe/contract/uploadcustomdocuments endpoint. The application validates uploaded files based on the user-controlled HTTP Content-Type value and…