VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 87 of 216
  • CVE-2024-45263HigOct 24, 2024
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upload interface allows the uploading of arbitrary files to the device. Once the device executes the files, it can lead to information leakage, enabling complete…

  • CVE-2024-10201HigOct 21, 2024
    risk 0.57cvss 8.8epss 0.01

    Administrative Management System from Wellchoose does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells.

  • CVE-2024-49398HigOct 17, 2024
    risk 0.57cvss epss 0.01

    The affected product is vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute code.

  • CVE-2020-36842HigOct 16, 2024
    risk 0.57cvss 8.8epss 0.01

    The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivid_upload_import_files and wpvivid_upload_files AJAX actions that allows low-level authenticated attackers to upload zip files…

  • CVE-2024-9981HigOct 15, 2024
    risk 0.57cvss 8.8epss 0.01

    The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regular privileges to upload a malicious PHP file first and then exploit this vulnerability to include the file, resulting in arbitrary code execution on the server.

  • CVE-2024-47823CriOct 8, 2024
    risk 0.57cvss 9.8epss 0.01

    Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/livewire prior to `2.12.7` and `v3.5.2`, the file extension of an uploaded file is guessed based on the MIME type. As a result, the actual file extension from…

  • CVE-2024-37869HigOct 4, 2024
    risk 0.57cvss 8.8epss 0.01

    File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "poster.php" file, and the uploaded file was received using the "$- FILES" variable

  • CVE-2024-37868HigOct 4, 2024
    risk 0.57cvss 8.8epss 0.01

    File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "sendreply.php" file, and the uploaded file was received using the "$- FILES" variable.

  • CVE-2024-47655HigOct 4, 2024
    risk 0.57cvss 8.8epss 0.01

    This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than the specified extension. An authenticated remote attacker could exploit this vulnerability by uploading malicious file, which could lead to remote code…

  • CVE-2024-46441HigSep 27, 2024
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in YPay 1.2.0 allows attackers to execute arbitrary code via a ZIP archive to themePutFile in app/common/util/Upload.php (called from app/admin/controller/ypay/Home.php). The file extension of an uncompressed file is not checked.

  • CVE-2024-47169HigSep 26, 2024
    risk 0.57cvss 8.8epss 0.01

    Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to upload arbitrary files to attacker-chosen locations on the server, including JavaScript, enabling the execution of…

  • CVE-2024-7772CriSep 26, 2024
    risk 0.57cvss 9.8epss 0.02

    The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file uploads due to a mishandled file type validation in the 'validate' function in all versions up to, and including, 4.6.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the…

  • CVE-2023-26690HigSep 25, 2024
    risk 0.57cvss 8.8epss 0.01

    File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/Editor component in the vendor or admin menu.

  • CVE-2024-46373HigSep 18, 2024
    risk 0.57cvss 8.8epss 0.00

    Dedecms V5.7.115 contains an arbitrary code execution via file upload vulnerability in the backend.

  • CVE-2024-7770HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.01

    The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload' function in all versions up to, and including, 6.5.5. This makes it…

  • CVE-2024-45171HigSep 5, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to upload dangerous files, for instance PHP code, to the C-MOR system. By analyzing the C-MOR web interface, it was found out that the upload…

  • CVE-2024-8330HigAug 30, 2024
    risk 0.57cvss 8.8epss 0.01

    6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload web shell scripts and use them to execute arbitrary system commands on the server.

  • CVE-2024-7559HigAug 23, 2024
    risk 0.57cvss 8.8epss 0.01

    The File Manager Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in the mk_file_folder_manager AJAX action in all versions up to, and including, 8.3.7. This makes it possible for authenticated attackers,…

  • CVE-2024-42780HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.01

    An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_genre" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2024-42779HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.01

    An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file.