VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,314)

page 35 of 216
  • CVE-2024-31615CriApr 25, 2024
    risk 0.64cvss 9.8epss 0.01

    ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php.

  • CVE-2023-31090CriApr 24, 2024
    risk 0.64cvss 9.9epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Upload a Web Shell to a Web Server.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates):…

  • CVE-2024-29661CriApr 22, 2024
    risk 0.64cvss 9.8epss 0.01

    A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload.

  • CVE-2024-32161CriApr 17, 2024
    risk 0.64cvss 9.8epss 0.01

    jizhiCMS 2.5 suffers from a File upload vulnerability.

  • CVE-2024-32514CriApr 17, 2024
    risk 0.64cvss 9.9epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Poll Maker & Voting Plugin Team (InfoTheme) WP Poll Maker.This issue affects WP Poll Maker: from n/a through 3.4.

  • CVE-2024-3863CriApr 16, 2024
    risk 0.64cvss 9.8epss 0.01

    The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.

  • CVE-2024-31286CriApr 7, 2024
    risk 0.64cvss 9.9epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a before 8.6.03.005.

  • CVE-2024-31280CriApr 7, 2024
    risk 0.64cvss 9.9epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.5.

  • CVE-2024-31012CriApr 3, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the upload.php file.

  • CVE-2024-30500CriMar 29, 2024
    risk 0.64cvss 9.9epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in CubeWP CubeWP – All-in-One Dynamic Content Framework.This issue affects CubeWP – All-in-One Dynamic Content Framework: from n/a through 1.1.12.

  • CVE-2024-28713CriMar 28, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Mblog Blog system v.3.5.0 allows an attacker to execute arbitrary code via a crafted file to the theme management feature.

  • CVE-2024-28441CriMar 22, 2024
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in magicflue v.7.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the messageid parameter of the mail/mailupdate.jsp endpoint.

  • CVE-2024-29859CriMar 21, 2024
    risk 0.64cvss 9.8epss 0.01

    In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload.

  • CVE-2024-29135CriMar 19, 2024
    risk 0.64cvss 9.9epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11.15.

  • CVE-2024-2599CriMar 18, 2024
    risk 0.64cvss 9.9epss 0.01

    File upload restriction evasion vulnerability in AMSS++ version 4.31. This vulnerability could allow an authenticated user to potentially obtain RCE through webshell, compromising the entire infrastructure.

  • CVE-2023-42286CriMar 14, 2024
    risk 0.64cvss 9.8epss 0.01

    There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system commands through a carefully crafted malicious payload.

  • CVE-2024-28423CriMar 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted YML file.

  • CVE-2023-41505CriMar 13, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the Add Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2024-1527CriMar 12, 2024
    risk 0.64cvss 9.8epss 0.01

    Unrestricted file upload vulnerability in CMS Made Simple, affecting version 2.2.14. This vulnerability allows an authenticated user to bypass the security measures of the upload functionality and potentially create a remote execution of commands via webshell.

  • CVE-2024-0864CriFeb 29, 2024
    risk 0.64cvss 9.8epss 0.01

    Enabling Simple Ajax Uploader plugin included in Laragon open-source software allows for a remote code execution (RCE) attack via an improper input validation in a file_upload.php file which serves as an example. By default, Laragon is not vulnerable until a user decides to use…