VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,297)

page 213 of 215
  • CVE-2022-4665HigDec 23, 2022
    risk 0.00cvss 8.8epss 0.01

    Unrestricted Upload of File with Dangerous Type in GitHub repository ampache/ampache prior to 5.5.6.

  • CVE-2022-4506HigDec 15, 2022
    risk 0.00cvss 8.8epss 0.01

    Unrestricted Upload of File with Dangerous Type in GitHub repository openemr/openemr prior to 7.0.0.2.

  • CVE-2022-36066CriSep 29, 2022
    risk 0.00cvss 9.1epss 0.02

    Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests-passed` branches, admins can upload a maliciously crafted Zip or Gzip Tar archive to write files at arbitrary locations and…

  • CVE-2022-31086HigJun 27, 2022
    risk 0.00cvss 8.8epss 0.02

    LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 incorrect regular expressions allow to upload PHP scripts to config/templates/pdf. This vulnerability could lead to a Remote…

  • CVE-2022-2128CriJun 20, 2022
    risk 0.00cvss 9.8epss 0.03

    Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.4.

  • CVE-2022-31041HigJun 13, 2022
    risk 0.00cvss 7.6epss 0.01

    Open Forms is an application for creating and publishing smart forms. Open Forms supports file uploads as one of the form field types. These fields can be configured to allow only certain file extensions to be uploaded by end users (e.g. only PDF / Excel / ...). The input…

  • CVE-2022-1752HigMay 21, 2022
    risk 0.00cvss 8.0epss 0.02

    Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.2.

  • CVE-2022-1345CriApr 13, 2022
    risk 0.00cvss 9.0epss 0.01

    Stored XSS viva .svg file upload in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.

  • CVE-2022-24837MedApr 11, 2022
    risk 0.00cvss 5.3epss 0.01

    HedgeDoc is an open-source, web-based, self-hosted, collaborative markdown editor. Images uploaded with HedgeDoc version 1.9.1 and later have an enumerable filename after the upload, resulting in potential information leakage of uploaded documents. This is especially relevant…

  • CVE-2022-1045MedApr 11, 2022
    risk 0.00cvss 5.4epss 0.02

    Stored XSS viva .svg file upload in GitHub repository polonel/trudesk prior to v1.2.0.

  • CVE-2021-28428CriApr 5, 2022
    risk 0.00cvss 9.8epss 0.01

    File upload vulnerability in HorizontCMS before 1.0.0-beta.3 via uploading a .htaccess and *.hello files using the Media Files upload functionality. The original file upload vulnerability (CVE-2020-27387) was remediated by restricting the PHP extensions; however, we confirmed…

  • CVE-2022-1033HigMar 23, 2022
    risk 0.00cvss 7.8epss 0.01

    Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6.

  • CVE-2021-3745MedOct 28, 2021
    risk 0.00cvss 6.6epss 0.01

    flatcore-cms is vulnerable to Unrestricted Upload of File with Dangerous Type

  • CVE-2021-3906MedOct 27, 2021
    risk 0.00cvss 6.5epss 0.01

    bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type

  • CVE-2021-41178HigOct 25, 2021
    risk 0.00cvss 8.8epss 0.02

    Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, a file traversal vulnerability makes an attacker able to download arbitrary SVG images from the host system, including user provided files. This could also be leveraged…

  • CVE-2021-39221MedOct 25, 2021
    risk 0.00cvss 6.4epss 0.01

    Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Contacts application prior to version 4.0.3 was vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. For exploitation, a user would need to right-click on a malicious file and open the file…

  • CVE-2021-40524HigSep 5, 2021
    risk 0.00cvss 7.5epss 0.04

    In Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of unbounded size, which may lead to denial of service or a server hang. This occurs because a certain greater-than-zero test does not anticipate an initial -1…

  • CVE-2021-38305HigAug 9, 2021
    risk 0.00cvss 7.8epss 0.02

    23andMe Yamale before 3.0.8 allows remote attackers to execute arbitrary code via a crafted schema file. The schema parser uses eval as part of its processing, and tries to protect from malicious expressions by limiting the builtins that are passed to the eval. When processing…

  • CVE-2021-28931HigJul 7, 2021
    risk 0.00cvss 8.8epss 0.01

    Arbitrary file upload vulnerability in Fork CMS 5.9.2 allows attackers to create or replace arbitrary files in the /themes directory via a crafted zip file uploaded to the Themes panel.

  • CVE-2021-32622MedMay 17, 2021
    risk 0.00cvss 4.2epss 0.00

    Matrix-React-SDK is a react-based SDK for inserting a Matrix chat/voip client into a web page. Before version 3.21.0, when uploading a file, the local file preview can lead to execution of scripts embedded in the uploaded file. This can only occur after several user interactions…