VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,314)

page 73 of 216
  • CVE-2023-36212HigAug 3, 2023
    risk 0.59cvss 8.8epss 0.26

    File Upload vulnerability in Total CMS v.1.7.4 allows a remote attacker to execute arbitrary code via a crafted PHP file to the edit page function.

  • CVE-2023-3486HigJul 25, 2023
    risk 0.59cvss 8.2epss 0.79

    An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated attacker to upload arbitrary files to the PaperCut NG host’s file storage. This could exhaust system resources and prevent the service from operating as…

  • CVE-2023-1721CriJun 24, 2023
    risk 0.59cvss 9.1epss 0.01

    Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does not correctly validate the thumbnails of the classes uploaded by the administrators.

  • CVE-2023-25132CriApr 24, 2023
    risk 0.59cvss 9.1epss 0.01

    Unrestricted upload of file with dangerous type vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and…

  • CVE-2022-46610HigJan 10, 2023
    risk 0.59cvss 8.8epss 0.18

    72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-32176CriOct 17, 2022
    risk 0.59cvss 9.0epss 0.01

    In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3b are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the "Compress Upload" functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will…

  • CVE-2022-32177CriOct 14, 2022
    risk 0.59cvss 9.0epss 0.01

    In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the 'Normal Upload' functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will…

  • CVE-2022-40878HigSep 27, 2022
    risk 0.59cvss 8.8epss 0.23

    In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to achieve Remote Code Execution (RCE).

  • CVE-2022-36386CriSep 21, 2022
    risk 0.59cvss 9.1epss 0.01

    Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.

  • CVE-2022-36667HigSep 14, 2022
    risk 0.59cvss 8.8epss 0.24

    Garage Management System 1.0 is vulnerable to the Remote Code Execution (RCE) due to the lack of filtering from the file upload function. The vulnerability exist during adding parts and from the upload function, the attacker can upload PHP Reverse Shell straight away to gain RCE.

  • CVE-2022-36264CriAug 8, 2022
    risk 0.59cvss 9.1epss 0.02

    In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists an Unauthenticated remote Arbitrary File Upload vulnerability which allows overwriting arbitrary files. A malicious actor can remotely upload a file of their choice and overwrite any file in the system by…

  • CVE-2022-28700CriJul 21, 2022
    risk 0.59cvss 9.1epss 0.02

    Authenticated Arbitrary File Creation via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.

  • CVE-2022-31362HigJun 23, 2022
    risk 0.59cvss 8.8epss 0.18

    Docebo Community Edition v4.0.5 and below was discovered to contain an arbitrary file upload vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

  • CVE-2022-27478HigApr 21, 2022
    risk 0.59cvss 8.8epss 0.20

    Victor v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component admin/profile.php?section=admin.

  • CVE-2022-27115CriApr 11, 2022
    risk 0.59cvss 9.8epss 0.29

    In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.

  • CVE-2022-28223CriMar 30, 2022
    risk 0.59cvss 9.1epss 0.01

    Tekon KIO devices through 2022-03-30 allow an authenticated admin user to escalate privileges to root by uploading a malicious Lua plugin.

  • CVE-2022-22952CriMar 23, 2022
    risk 0.59cvss 9.1epss 0.02

    VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains a file upload vulnerability. A malicious actor with administrative access to the VMware App Control administration interface may be able to…

  • CVE-2022-24387CriMar 14, 2022
    risk 0.59cvss 9.1epss 0.02

    With administrator or admin privileges the application can be tricked into overwriting files in app_data/Config folder, e.g. the systemsettings.xml file. THis is possible in SmarterTrack v100.0.8019.14010

  • CVE-2022-23375HigFeb 19, 2022
    risk 0.59cvss 8.8epss 0.20

    WikiDocs version 0.1.18 has an authenticated remote code execution vulnerability. An attacker can upload a malicious file using the image upload form through index.php.

  • CVE-2021-38471CriOct 22, 2021
    risk 0.59cvss 9.1epss 0.01

    There are multiple API function codes that permit data writing to any file, which may allow an attacker to modify existing files or create new files.