VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 91 of 216
  • CVE-2023-50692HigDec 28, 2023
    risk 0.57cvss 8.8epss 0.01

    File Upload vulnerability in JIZHICMS v.2.5, allows remote attacker to execute arbitrary code via a crafted file uploaded and downloaded to the download_url parameter in the app/admin/exts/ directory.

  • CVE-2023-5931HigDec 26, 2023
    risk 0.57cvss 8.8epss 0.01

    The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 does not validate files to be uploaded, which could allow attackers with a low-privilege account (e.g. subscribers) to upload arbitrary files such as PHP on the server

  • CVE-2023-5673HigDec 26, 2023
    risk 0.57cvss 8.8epss 0.01

    The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file extensions uploading files to attach to emails, allowing attackers to upload PHP files, leading to remote code execution.

  • CVE-2023-23970HigDec 20, 2023
    risk 0.57cvss 8.8epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in WooRockets Corsa.This issue affects Corsa: from n/a through 1.5.

  • CVE-2023-4311HigDec 18, 2023
    risk 0.57cvss 8.8epss 0.01

    The Vrm 360 3D Model Viewer WordPress plugin through 1.2.1 is vulnerable to arbitrary file upload due to insufficient checks in a plugin shortcode.

  • CVE-2023-48394HigDec 15, 2023
    risk 0.57cvss 8.8epss 0.01

    Kaifa Technology WebITR is an online attendance system, its file uploading function does not restrict upload of file with dangerous type. A remote attacker with regular user privilege can exploit this vulnerability to upload arbitrary files to perform arbitrary command or…

  • CVE-2023-5953HigDec 4, 2023
    risk 0.57cvss 8.8epss 0.00

    The Welcart e-Commerce WordPress plugin before 2.9.5 does not validate files to be uploaded, as well as does not have authorisation and CSRF in an AJAX action handling such upload. As a result, any authenticated users, such as subscriber could upload arbitrary files, such as PHP…

  • CVE-2023-48966HigDec 4, 2023
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the component /admin/api.upload/file of ThinkAdmin v6.1.53 allows attackers to execute arbitrary code via a crafted Zip file.

  • CVE-2023-48965HigDec 4, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in the component /admin/api.plugs/script of ThinkAdmin v6.1.53 allows attackers to getshell via providing a crafted URL to download a malicious PHP file.

  • CVE-2023-49052HigNov 30, 2023
    risk 0.57cvss 8.8epss 0.02

    File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function in the created forms component.

  • CVE-2023-29770HigNov 28, 2023
    risk 0.57cvss 8.8epss 0.01

    In Sentrifugo 3.5, the AssetsController::uploadsaveAction function allows an authenticated attacker to upload any file without extension filtering.

  • CVE-2023-39548HigNov 17, 2023
    risk 0.57cvss 8.8epss 0.01

    CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command.

  • CVE-2023-33480HigNov 7, 2023
    risk 0.57cvss 8.8epss 0.02

    RemoteClinic 2.0 contains a critical vulnerability chain that can be exploited by a remote attacker with low-privileged user credentials to create admin users, escalate privileges, and execute arbitrary code on the target system via a PHP shell. The vulnerabilities are caused by…

  • CVE-2023-41357HigNov 3, 2023
    risk 0.57cvss 8.8epss 0.01

    Galaxy Software Services Corporation Vitals ESP is an online knowledge base management portal, it has insufficient filtering and validation during file upload. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload and execute…

  • CVE-2023-46428HigNov 1, 2023
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in HadSky v7.12.10 allows attackers to execute arbitrary code via a crafted file.

  • CVE-2023-1713HigNov 1, 2023
    risk 0.57cvss 8.8epss 0.01

    Insecure temporary file creation in bitrix/modules/crm/lib/order/import/instagram.php in Bitrix24 22.0.300 hosted on Apache HTTP Server allows remote authenticated attackers to execute arbitrary code via uploading a crafted ".htaccess" file.

  • CVE-2023-46815HigOct 27, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. An Unrestricted File Upload vulnerability has been identified in the Notes module. By using a crafted request, custom PHP code can be injected via the Notes module because of missing input validation. An…

  • CVE-2023-26578HigOct 25, 2023
    risk 0.57cvss 8.8epss 0.01

    Arbitrary file upload to web root in the IDAttend’s IDWeb application 3.1.013 allows authenticated attackers to upload dangerous files to web root such as ASP or ASPX, gaining command execution on the affected server.

  • CVE-2023-41631HigOct 17, 2023
    risk 0.57cvss 8.8epss 0.01

    eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the file upload function.

  • CVE-2023-45353HigOct 9, 2023
    risk 0.57cvss 8.8epss 0.01

    Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to execute arbitrary code on the operating system by leveraging the Common Management Portal web interface for Authenticated remote upload and creation of…