VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 88 of 216
  • CVE-2024-42778HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.01

    An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_playlist" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2024-42676HigAug 15, 2024
    risk 0.57cvss 8.8epss 0.01

    File Upload vulnerability in Huizhi enterprise resource management system v.1.0 and before allows a remote attacker to execute arbitrary code via the /nssys/common/Upload. Aspx? Action=DNPageAjaxPostBack component

  • CVE-2024-6707HigAug 7, 2024
    risk 0.57cvss 8.8epss 0.01

    Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traversal vulnerability.

  • CVE-2024-41913HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly sanitize User input.

  • CVE-2024-6315HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.01

    The Blox Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handleUploadFile' function in all versions up to, and including, 1.0.65. This makes it possible for authenticated attackers, with contributor-level and…

  • CVE-2024-6117HigAug 5, 2024
    risk 0.57cvss 8.8epss 0.01

    A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform arbitrary system commands via a crafted ASP file.

  • CVE-2024-7257CriAug 3, 2024
    risk 0.57cvss 9.8epss 0.01

    The YayExtra – WooCommerce Extra Product Options plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_upload_file function in all versions up to, and including, 1.3.7. This makes it possible for unauthenticated…

  • CVE-2024-6431HigJul 27, 2024
    risk 0.57cvss 8.8epss 0.01

    The Media.net Ads Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and missing capability check in the 'sendMail' function in all versions up to, and including, 2.10.13. This makes it possible for authenticated attackers,…

  • CVE-2024-6756HigJul 24, 2024
    risk 0.57cvss 8.8epss 0.01

    The Social Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpw_auto_poster_get_image_path' function in all versions up to, and including, 5.3.14. This makes it possible for authenticated attackers, with…

  • CVE-2024-5630HigJul 15, 2024
    risk 0.57cvss 8.8epss 0.01

    The Insert or Embed Articulate Content into WordPress plugin before 4.3000000024 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.

  • CVE-2024-5080HigJul 13, 2024
    risk 0.57cvss 8.8epss 0.01

    The wp-eMember WordPress plugin before 10.6.6 does not validate files to be uploaded, which could allow admins to upload arbitrary files such as PHP on the server

  • CVE-2024-40551HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.00

    An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-40550HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-40549HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlace of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-40548HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-40546HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-40545HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2023-7061HigJul 10, 2024
    risk 0.57cvss 8.8epss 0.01

    The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 2.5.3. This makes it possible for authenticated attackers with contributor access or above to upload arbitrary files on the affected site's…

  • CVE-2024-39865HigJul 9, 2024
    risk 0.57cvss 8.8epss 0.00

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows users to upload encrypted backup files. As part of this backup, files can be restored without correctly checking the path of the restored file. This…

  • CVE-2024-6161HigJul 9, 2024
    risk 0.57cvss 8.8epss 0.01

    The Default Thumbnail Plus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'get_cache_image' function in all versions up to, and including, 1.0.2.3. This makes it possible for authenticated attackers, with contributor-level…