VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 93 of 216
  • CVE-2023-34126HigJul 13, 2023
    risk 0.57cvss 8.8epss 0.01

    Vulnerability in SonicWall GMS and Analytics allows an authenticated attacker to upload files on the underlying filesystem with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

  • CVE-2023-34193HigJul 6, 2023
    risk 0.57cvss 8.8epss 0.01

    File Upload vulnerability in Zimbra ZCS 8.8.15 allows an authenticated privileged user to execute arbitrary code and obtain sensitive information via the ClientUploader function.

  • CVE-2020-21861HigJul 6, 2023
    risk 0.57cvss 8.8epss 0.01

    File upload vulnerability in DuxCMS 2.1 allows attackers to execute arbitrary php code via duxcms/AdminUpload/upload.

  • CVE-2020-20210HigJun 26, 2023
    risk 0.57cvss 8.8epss 0.01

    Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.

  • CVE-2023-36630HigJun 25, 2023
    risk 0.57cvss 8.8epss 0.01

    In CloudPanel before 2.3.1, insecure file upload leads to privilege escalation and authentication bypass.

  • CVE-2020-21489CriJun 20, 2023
    risk 0.57cvss 9.8epss 0.01

    File Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.php?r=admin-user%2Fupdate-self component.

  • CVE-2020-21325HigJun 20, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in WUZHI CMS v.4.1.0 allows a remote attacker to execute arbitrary code via the set_chache method of the function\common.func.php file.

  • CVE-2020-21174CriJun 20, 2023
    risk 0.57cvss 9.8epss 0.01

    File Upload vulenrability in liufee CMS v.2.0.7.1 allows a remote attacker to execute arbitrary code via the image suffix function.

  • CVE-2020-20067HigJun 20, 2023
    risk 0.57cvss 8.8epss 0.01

    File upload vulnerability in ebCMS v.1.1.0 allows a remote attacker to execute arbitrary code via the upload type parameter.

  • CVE-2023-35808HigJun 17, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. An Unrestricted File Upload vulnerability has been identified in the Notes module. By using crafted requests, custom PHP code can be injected and executed through the Notes module because of…

  • CVE-2023-3295HigJun 17, 2023
    risk 0.57cvss 8.8epss 0.01

    The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file uploads due to missing file type validation of files in the file manager functionality in versions up to, and including, 1.5.66 . This makes it possible for…

  • CVE-2023-33253HigJun 12, 2023
    risk 0.57cvss 8.8epss 0.03

    LabCollector 6.0 though 6.15 allows remote code execution. An authenticated remote low-privileged user can upload an executable PHP file and execute system commands. The vulnerability is in the message function, and is due to insufficient validation of the file (such as…

  • CVE-2023-33498HigJun 7, 2023
    risk 0.57cvss 8.8epss 0.01

    alist <=3.16.3 is vulnerable to Incorrect Access Control. Low privilege accounts can upload any file.

  • CVE-2023-33601HigJun 7, 2023
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in /admin.php?c=upload of phpok v6.4.100 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-4949HigJun 7, 2023
    risk 0.57cvss 8.8epss 0.02

    The AdSanity plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_upload' function in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers with Contributor+ level privileges to upload…

  • CVE-2021-4382HigJun 7, 2023
    risk 0.57cvss 8.8epss 0.02

    The Recently plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the fetch_external_image() function in versions up to, and including, 3.0.4. This makes it possible for authenticated attackers to upload arbitrary files on the…

  • CVE-2021-4354HigJun 7, 2023
    risk 0.57cvss 8.8epss 0.02

    The PWA for WP & AMP for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pwaforwp_splashscreen_uploader function in versions up to, and including, 1.7.32. This makes it possible for authenticated attackers to upload arbitrary files on…

  • CVE-2020-36701HigJun 7, 2023
    risk 0.57cvss 8.8epss 0.02

    The Page Builder: KingComposer plugin for WordPress is vulnerable to Arbitrary File Uploads in versions up to, and including, 2.9.3 via the 'process_bulk_action' function in the 'kingcomposer/includes/kc.extensions.php' file. This makes it possible for authenticated users with…

  • CVE-2023-28699HigJun 2, 2023
    risk 0.57cvss 8.8epss 0.01

    Wade Graphic Design FANTSY has a vulnerability of insufficient filtering for file type in its file update function. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload a PHP file containing a webshell to perform arbitrary system…

  • CVE-2023-28353HigMay 31, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Faronics Insight 10.0.19045 on Windows. An unauthenticated attacker is able to upload any type of file to any location on the Teacher Console's computer, enabling a variety of different exploitation paths including code execution. It is also possible…