CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,314)
page 73 of 216| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36212 | Hig | 0.59 | 8.8 | 0.26 | Aug 3, 2023 | File Upload vulnerability in Total CMS v.1.7.4 allows a remote attacker to execute arbitrary code via a crafted PHP file to the edit page function. | ||
| CVE-2023-3486 | Hig | 0.59 | 8.2 | 0.79 | Jul 25, 2023 | An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated attacker to upload arbitrary files to the PaperCut NG host’s file storage. This could exhaust system resources and prevent the service from operating as… | ||
| CVE-2023-1721 | Cri | 0.59 | 9.1 | 0.01 | Jun 24, 2023 | Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does not correctly validate the thumbnails of the classes uploaded by the administrators. | ||
| CVE-2023-25132 | Cri | 0.59 | 9.1 | 0.01 | Apr 24, 2023 | Unrestricted upload of file with dangerous type vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and… | ||
| CVE-2022-46610 | — | Hig | 0.59 | 8.8 | 0.18 | Jan 10, 2023 | 72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |
| CVE-2022-32176 | Cri | 0.59 | 9.0 | 0.01 | Oct 17, 2022 | In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3b are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the "Compress Upload" functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will… | ||
| CVE-2022-32177 | Cri | 0.59 | 9.0 | 0.01 | Oct 14, 2022 | In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the 'Normal Upload' functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will… | ||
| CVE-2022-40878 | Hig | 0.59 | 8.8 | 0.23 | Sep 27, 2022 | In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to achieve Remote Code Execution (RCE). | ||
| CVE-2022-36386 | Cri | 0.59 | 9.1 | 0.01 | Sep 21, 2022 | Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress. | ||
| CVE-2022-36667 | Hig | 0.59 | 8.8 | 0.24 | Sep 14, 2022 | Garage Management System 1.0 is vulnerable to the Remote Code Execution (RCE) due to the lack of filtering from the file upload function. The vulnerability exist during adding parts and from the upload function, the attacker can upload PHP Reverse Shell straight away to gain RCE. | ||
| CVE-2022-36264 | Cri | 0.59 | 9.1 | 0.02 | Aug 8, 2022 | In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists an Unauthenticated remote Arbitrary File Upload vulnerability which allows overwriting arbitrary files. A malicious actor can remotely upload a file of their choice and overwrite any file in the system by… | ||
| CVE-2022-28700 | Cri | 0.59 | 9.1 | 0.02 | Jul 21, 2022 | Authenticated Arbitrary File Creation via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress. | ||
| CVE-2022-31362 | Hig | 0.59 | 8.8 | 0.18 | Jun 23, 2022 | Docebo Community Edition v4.0.5 and below was discovered to contain an arbitrary file upload vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | ||
| CVE-2022-27478 | Hig | 0.59 | 8.8 | 0.20 | Apr 21, 2022 | Victor v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component admin/profile.php?section=admin. | ||
| CVE-2022-27115 | Cri | 0.59 | 9.8 | 0.29 | Apr 11, 2022 | In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload. | ||
| CVE-2022-28223 | Cri | 0.59 | 9.1 | 0.01 | Mar 30, 2022 | Tekon KIO devices through 2022-03-30 allow an authenticated admin user to escalate privileges to root by uploading a malicious Lua plugin. | ||
| CVE-2022-22952 | Cri | 0.59 | 9.1 | 0.02 | Mar 23, 2022 | VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains a file upload vulnerability. A malicious actor with administrative access to the VMware App Control administration interface may be able to… | ||
| CVE-2022-24387 | Cri | 0.59 | 9.1 | 0.02 | Mar 14, 2022 | With administrator or admin privileges the application can be tricked into overwriting files in app_data/Config folder, e.g. the systemsettings.xml file. THis is possible in SmarterTrack v100.0.8019.14010 | ||
| CVE-2022-23375 | Hig | 0.59 | 8.8 | 0.20 | Feb 19, 2022 | WikiDocs version 0.1.18 has an authenticated remote code execution vulnerability. An attacker can upload a malicious file using the image upload form through index.php. | ||
| CVE-2021-38471 | Cri | 0.59 | 9.1 | 0.01 | Oct 22, 2021 | There are multiple API function codes that permit data writing to any file, which may allow an attacker to modify existing files or create new files. |
- risk 0.59cvss 8.8epss 0.26
File Upload vulnerability in Total CMS v.1.7.4 allows a remote attacker to execute arbitrary code via a crafted PHP file to the edit page function.
- risk 0.59cvss 8.2epss 0.79
An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated attacker to upload arbitrary files to the PaperCut NG host’s file storage. This could exhaust system resources and prevent the service from operating as…
- risk 0.59cvss 9.1epss 0.01
Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does not correctly validate the thumbnails of the classes uploaded by the administrators.
- risk 0.59cvss 9.1epss 0.01
Unrestricted upload of file with dangerous type vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and…
- risk 0.59cvss 8.8epss 0.18
72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.59cvss 9.0epss 0.01
In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3b are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the "Compress Upload" functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will…
- risk 0.59cvss 9.0epss 0.01
In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the 'Normal Upload' functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will…
- risk 0.59cvss 8.8epss 0.23
In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to achieve Remote Code Execution (RCE).
- risk 0.59cvss 9.1epss 0.01
Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.
- risk 0.59cvss 8.8epss 0.24
Garage Management System 1.0 is vulnerable to the Remote Code Execution (RCE) due to the lack of filtering from the file upload function. The vulnerability exist during adding parts and from the upload function, the attacker can upload PHP Reverse Shell straight away to gain RCE.
- risk 0.59cvss 9.1epss 0.02
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists an Unauthenticated remote Arbitrary File Upload vulnerability which allows overwriting arbitrary files. A malicious actor can remotely upload a file of their choice and overwrite any file in the system by…
- risk 0.59cvss 9.1epss 0.02
Authenticated Arbitrary File Creation via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.
- risk 0.59cvss 8.8epss 0.18
Docebo Community Edition v4.0.5 and below was discovered to contain an arbitrary file upload vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
- risk 0.59cvss 8.8epss 0.20
Victor v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component admin/profile.php?section=admin.
- risk 0.59cvss 9.8epss 0.29
In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.
- risk 0.59cvss 9.1epss 0.01
Tekon KIO devices through 2022-03-30 allow an authenticated admin user to escalate privileges to root by uploading a malicious Lua plugin.
- risk 0.59cvss 9.1epss 0.02
VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains a file upload vulnerability. A malicious actor with administrative access to the VMware App Control administration interface may be able to…
- risk 0.59cvss 9.1epss 0.02
With administrator or admin privileges the application can be tricked into overwriting files in app_data/Config folder, e.g. the systemsettings.xml file. THis is possible in SmarterTrack v100.0.8019.14010
- risk 0.59cvss 8.8epss 0.20
WikiDocs version 0.1.18 has an authenticated remote code execution vulnerability. An attacker can upload a malicious file using the image upload form through index.php.
- risk 0.59cvss 9.1epss 0.01
There are multiple API function codes that permit data writing to any file, which may allow an attacker to modify existing files or create new files.