VYPR

OneupUploaderBundle

by 1up-lab

CVEs (1)

  • CVE-2020-5237Feb 5, 2020
    risk 0.00cvss epss 0.05

    Multiple relative path traversal vulnerabilities in the oneup/uploader-bundle before 1.9.3 and 2.1.5 allow remote attackers to upload, copy, and modify files on the filesystem (potentially leading to arbitrary code execution) via the (1) filename parameter to…