VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,297)

page 212 of 215
  • CVE-2024-5278MedJun 6, 2024
    risk 0.00cvss 6.1epss 0.01

    gaizhenbiao/chuanhuchatgpt is vulnerable to an unrestricted file upload vulnerability due to insufficient validation of uploaded file types in its `/upload` endpoint. Specifically, the `handle_file_upload` function does not sanitize or validate the file extension or content type…

  • CVE-2024-33438HigApr 29, 2024
    risk 0.00cvss 8.0epss 0.01

    File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file.

  • CVE-2024-2221CriApr 10, 2024
    risk 0.00cvss 9.8epss 0.02

    qdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the `/collections/{COLLECTION}/snapshots/upload` endpoint, specifically through the `snapshot` parameter. This vulnerability allows attackers to upload and overwrite any file on the…

  • CVE-2024-25410MedFeb 26, 2024
    risk 0.00cvss 6.5epss 0.01

    flusity-CMS 2.33 is vulnerable to Unrestricted Upload of File with Dangerous Type in update_setting.php.

  • CVE-2024-25636HigFeb 19, 2024
    risk 0.00cvss 7.1epss 0.01

    Misskey is an open source, decentralized social media platform with ActivityPub support. Prior to version 2024.2.0, when fetching remote Activity Streams objects, Misskey doesn't check that the response from the remote server has a `Content-Type` header value of the Activity…

  • CVE-2024-25623HigFeb 19, 2024
    risk 0.00cvss 8.5epss 0.01

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.2.7, 4.1.15, 4.0.15, and 3.5.19, when fetching remote statuses, Mastodon doesn't check that the response from the remote server has a `Content-Type` header value of the Activity…

  • CVE-2023-52086HigDec 26, 2023
    risk 0.00cvss 8.1epss 0.01

    resumable.php (aka PHP backend for resumable.js) 0.1.4 before 3c6dbf5 allows arbitrary file upload anywhere in the filesystem via ../ in multipart/form-data content to upload.php. (File overwrite hasn't been possible with the code available in GitHub in recent years, however.)

  • CVE-2023-6850MedDec 16, 2023
    risk 0.00cvss 6.3epss 0.01

    A vulnerability was found in kalcaddle KodExplorer up to 4.51.03. It has been declared as critical. This vulnerability affects unknown code of the file /index.php?pluginApp/to/yzOffice/getFile of the component API Endpoint Handler. The manipulation of the argument path/file…

  • CVE-2023-4226HigNov 28, 2023
    risk 0.00cvss 8.8epss 0.02

    Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.

  • CVE-2023-4225HigNov 28, 2023
    risk 0.00cvss 8.8epss 0.02

    Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.

  • CVE-2023-4224HigNov 28, 2023
    risk 0.00cvss 8.8epss 0.02

    Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.

  • CVE-2023-4223HigNov 28, 2023
    risk 0.00cvss 8.8epss 0.02

    Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.

  • CVE-2023-6127MedNov 14, 2023
    risk 0.00cvss 5.4epss 0.00

    Unrestricted Upload of File with Dangerous Type in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

  • CVE-2023-42803MedOct 30, 2023
    risk 0.00cvss 5.3epss 0.01

    BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestricted file upload, where the insertDocument API call does not validate the given file extension before saving the file, and does not remove it in case of…

  • CVE-2023-40183HigSep 21, 2023
    risk 0.00cvss 7.5epss 0.01

    DataEase is an open source data visualization and analysis tool. Prior to version 1.18.11, DataEase has a vulnerability that allows an attacker to to obtain user cookies. The program only uses the `ImageIO.read()` method to determine whether the file is an image file or not.…

  • CVE-2023-39346HigAug 4, 2023
    risk 0.00cvss 8.8epss 0.01

    LinuxASMCallGraph is software for drawing the call graph of the programming code. Linux ASMCallGraph before commit 20dba06bd1a3cf260612d4f21547c25002121cd5 allows attackers to cause a remote code execution on the server side via uploading a crafted ZIP file due to incorrect…

  • CVE-2023-4159HigAug 4, 2023
    risk 0.00cvss 8.8epss 0.01

    Unrestricted Upload of File with Dangerous Type in GitHub repository omeka/omeka-s prior to 4.0.3.

  • CVE-2023-3491HigJun 30, 2023
    risk 0.00cvss 8.8epss 0.01

    Unrestricted Upload of File with Dangerous Type in GitHub repository fossbilling/fossbilling prior to 0.5.3.

  • CVE-2023-28833LowMar 30, 2023
    risk 0.00cvss 2.4epss 0.01

    Nextcloud server is an open source home cloud implementation. In affected versions admins of a server were able to upload a logo or a favicon and to provided a file name which was not restricted and could overwrite files in the appdata directory. Administrators may have access…

  • CVE-2023-23607CriJan 20, 2023
    risk 0.00cvss 9.8epss 0.02

    erohtar/Dasherr is a dashboard for self-hosted services. In affected versions unrestricted file upload allows any unauthenticated user to execute arbitrary code on the server. The file /www/include/filesave.php allows for any file to uploaded to anywhere. If an attacker uploads…