VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,434)

page 36 of 222
  • CVE-2024-35375CriMay 23, 2024
    risk 0.64cvss 9.8epss 0.00

    There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.114 of DedeCMS

  • CVE-2024-35080CriMay 23, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the gok4 method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading a crafted .jsp file.

  • CVE-2024-35079CriMay 23, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the uploadAudio method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading a crafted .jsp file.

  • CVE-2024-5084CriMay 23, 2024
    risk 0.64cvss 9.8epss 0.51

    The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to…

  • CVE-2024-34982CriMay 17, 2024
    risk 0.64cvss 9.8epss 0.05

    An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-4825CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker could upload files to the server, compromising the entire infrastructure.

  • CVE-2024-4560CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the chatbot_chatgpt_upload_file_to_assistant function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated…

  • CVE-2024-34411CriMay 14, 2024
    risk 0.64cvss 9.9epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Thomas Scholl canvasio3D Light.This issue affects canvasio3D Light: from n/a through 2.5.0.

  • CVE-2024-33120CriMay 7, 2024
    risk 0.64cvss 9.8epss 0.01

    Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerability allows attackers to execute arbitrary code via a crafted JSP file.

  • CVE-2024-33786CriMay 3, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in Zhongcheng Kexin Ticketing Management Platform 20.04 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2023-51590CriMay 3, 2024
    risk 0.64cvss 9.8epss 0.01

    Voltronic Power ViewPower Pro UpLoadAction Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Voltronic Power ViewPower Pro. Authentication is not required to exploit…

  • CVE-2024-2667CriMay 2, 2024
    risk 0.64cvss 9.8epss 0.06

    The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation in the /wp-json/instawp-connect/v1/config REST API endpoint in all versions up to, and including, 0.1.0.22. This makes it…

  • CVE-2024-4306CriApr 29, 2024
    risk 0.64cvss 9.9epss 0.01

    Critical unrestricted file upload vulnerability in HubBank affecting version 1.0.2. This vulnerability allows a registered user to upload malicious PHP files via upload document fields, resulting in webshell execution.

  • CVE-2024-31615CriApr 25, 2024
    risk 0.64cvss 9.8epss 0.01

    ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php.

  • CVE-2023-31090CriApr 24, 2024
    risk 0.64cvss 9.9epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Upload a Web Shell to a Web Server.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates):…

  • CVE-2024-29661CriApr 22, 2024
    risk 0.64cvss 9.8epss 0.01

    A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload.

  • CVE-2024-32161CriApr 17, 2024
    risk 0.64cvss 9.8epss 0.01

    jizhiCMS 2.5 suffers from a File upload vulnerability.

  • CVE-2024-32514CriApr 17, 2024
    risk 0.64cvss 9.9epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Poll Maker & Voting Plugin Team (InfoTheme) WP Poll Maker.This issue affects WP Poll Maker: from n/a through 3.4.

  • CVE-2024-3863CriApr 16, 2024
    risk 0.64cvss 9.8epss 0.01

    The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.

  • CVE-2024-31286CriApr 7, 2024
    risk 0.64cvss 9.9epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a before 8.6.03.005.