CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,314)
page 49 of 216| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-39384 | Cri | 0.64 | 9.8 | 0.01 | Mar 20, 2022 | DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component /utils/ToHtmlServlet.java. | ||
| CVE-2021-45835 | Cri | 0.64 | 9.8 | 0.03 | Mar 18, 2022 | The Online Admission System 1.0 allows an unauthenticated attacker to upload or transfer files of dangerous types to the application through documents.php, which may be used to execute malicious code or lead to code execution. | ||
| CVE-2021-45834 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically processed within the product's environment or lead to arbitrary code execution. | ||
| CVE-2021-45040 | Cri | 0.64 | 9.8 | 0.03 | Mar 17, 2022 | The Spatie media-library-pro library through 1.17.10 and 2.x through 2.1.6 for Laravel allows remote attackers to upload executable files via the uploads route. | ||
| CVE-2022-25495 | Cri | 0.64 | 9.8 | 0.02 | Mar 15, 2022 | The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-24652 | Cri | 0.64 | 9.8 | 0.03 | Mar 10, 2022 | sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in php code execution in /admin/upload/upload. | ||
| CVE-2022-24651 | Cri | 0.64 | 9.8 | 0.03 | Mar 10, 2022 | sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in PHP code execution through /user/upload/upload. | ||
| CVE-2022-25016 | Cri | 0.64 | 9.8 | 0.02 | Mar 2, 2022 | Home Owners Collection Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /student_attendance/index.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-25411 | Cri | 0.64 | 9.8 | 0.03 | Feb 28, 2022 | A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-24553 | Cri | 0.64 | 9.8 | 0.03 | Feb 21, 2022 | An issue was found in Zfaka <= 1.4.5. The verification of the background file upload function check is not strict, resulting in remote command execution. | ||
| CVE-2021-46036 | Cri | 0.64 | 9.8 | 0.04 | Feb 18, 2022 | An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code. | ||
| CVE-2022-24984 | Cri | 0.64 | 9.8 | 0.03 | Feb 16, 2022 | Forms generated by JQueryForm.com before 2022-02-05 (if file-upload capability is enabled) allow remote unauthenticated attackers to upload executable files and achieve remote code execution. This occurs because file-extension checks occur on the client side, and because not all… | ||
| CVE-2022-23390 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2022 | An issue in the getType function of BBS Forum v5.3 and below allows attackers to upload arbitrary files. | ||
| CVE-2021-22803 | Cri | 0.64 | 9.8 | 0.02 | Feb 11, 2022 | A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution through a number of paths, when an attacker, writes arbitrary files to folders in context of the DC module, by sending constructed messages on the network.… | ||
| CVE-2020-13675 | Cri | 0.64 | 9.8 | 0.01 | Feb 11, 2022 | Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access bypass vulnerability. An attacker might be able to upload files that bypass the file validation process implemented by… | ||
| CVE-2021-46428 | Cri | 0.64 | 9.8 | 0.03 | Jan 27, 2022 | A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versions via the bot_avatar parameter in SystemSettings.php. | ||
| CVE-2021-46386 | Cri | 0.64 | 9.8 | 0.03 | Jan 26, 2022 | File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload. | ||
| CVE-2021-46033 | Cri | 0.64 | 9.8 | 0.01 | Jan 25, 2022 | In ForestBlog, as of 2021-12-28, File upload can bypass verification. | ||
| CVE-2022-23315 | Cri | 0.64 | 9.8 | 0.02 | Jan 21, 2022 | MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do. | ||
| CVE-2022-22929 | Cri | 0.64 | 9.8 | 0.03 | Jan 21, 2022 | MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbitrary code via a crafted ZIP file. |
- risk 0.64cvss 9.8epss 0.01
DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component /utils/ToHtmlServlet.java.
- risk 0.64cvss 9.8epss 0.03
The Online Admission System 1.0 allows an unauthenticated attacker to upload or transfer files of dangerous types to the application through documents.php, which may be used to execute malicious code or lead to code execution.
- risk 0.64cvss 9.8epss 0.02
An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically processed within the product's environment or lead to arbitrary code execution.
- risk 0.64cvss 9.8epss 0.03
The Spatie media-library-pro library through 1.17.10 and 2.x through 2.1.6 for Laravel allows remote attackers to upload executable files via the uploads route.
- risk 0.64cvss 9.8epss 0.02
The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arbitrary code via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.03
sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in php code execution in /admin/upload/upload.
- risk 0.64cvss 9.8epss 0.03
sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in PHP code execution through /user/upload/upload.
- risk 0.64cvss 9.8epss 0.02
Home Owners Collection Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /student_attendance/index.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.03
A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.03
An issue was found in Zfaka <= 1.4.5. The verification of the background file upload function check is not strict, resulting in remote command execution.
- risk 0.64cvss 9.8epss 0.04
An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.03
Forms generated by JQueryForm.com before 2022-02-05 (if file-upload capability is enabled) allow remote unauthenticated attackers to upload executable files and achieve remote code execution. This occurs because file-extension checks occur on the client side, and because not all…
- risk 0.64cvss 9.8epss 0.01
An issue in the getType function of BBS Forum v5.3 and below allows attackers to upload arbitrary files.
- risk 0.64cvss 9.8epss 0.02
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution through a number of paths, when an attacker, writes arbitrary files to folders in context of the DC module, by sending constructed messages on the network.…
- risk 0.64cvss 9.8epss 0.01
Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access bypass vulnerability. An attacker might be able to upload files that bypass the file validation process implemented by…
- risk 0.64cvss 9.8epss 0.03
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versions via the bot_avatar parameter in SystemSettings.php.
- risk 0.64cvss 9.8epss 0.03
File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload.
- risk 0.64cvss 9.8epss 0.01
In ForestBlog, as of 2021-12-28, File upload can bypass verification.
- risk 0.64cvss 9.8epss 0.02
MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do.
- risk 0.64cvss 9.8epss 0.03
MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbitrary code via a crafted ZIP file.