CWE-434— Unrestricted Upload of File with Dangerous Type
3,921 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 26 of 79
- CVE-2022-22482MEDIUMCVSS 6.5EG 6.52022-05-17
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow an authenticated user to upload files that could fill up the filesystem and cause a denial of service. IBM X-Force ID: 225977.
- CVE-2022-2268HIGHCVSS 7.2EG 7.22022-07-04
The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary fi…
- CVE-2022-22929CRITICALCVSS 9.8EG 9.82022-01-21
MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbitrary code via a crafted ZIP file.
- CVE-2022-22952CRITICALCVSS 9.1EG 9.12022-03-23
VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains a file upload vulnerability. A malicious actor with administrative access to the VMware App Control admin…
- CVE-2022-2297MEDIUMCVSS 6.3EG 8.82022-07-12
A vulnerability, which was classified as critical, was found in SourceCodester Clinics Patient Management System 2.0. Affected is an unknown function of the file /pms/update_user.php?user_id=1. The manipulation of the argument profile_pict…
- CVE-2022-23026MEDIUMCVSS 4.3EG 4.32022-01-25
On BIG-IP ASM & Advanced WAF version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, an authenticated user with low privileges, such as a guest, can upload data using an undisclo…
- CVE-2022-23043HIGHCVSS 7.2EG 7.22022-02-24
Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extension. Then an attacker can upload a malicious file, intercept the request and change the ex…
- CVE-2022-23048HIGHCVSS 7.2EG 7.22022-02-09
Exponent CMS 2.6.0patch2 allows an authenticated admin user to upload a malicious extension in the format of a ZIP file with a PHP file inside it. After upload it, the PHP file will be placed at "themes/simpletheme/{rce}.php" from where ca…
- CVE-2022-23050HIGHCVSS 7.2EG 7.22022-05-24
ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working' folder through the 'Upload Files / Binaries' functionality.
- CVE-2022-23155HIGHCVSS 7.2EG 7.22022-04-01
Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability. A malicious user with admin privileges can exploit this vulnerability in order to execute arbitrary code on the system.
- CVE-2022-23315CRITICALCVSS 9.8EG 9.82022-01-21
MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do.
- CVE-2022-23329CRITICALCVSS 9.8EG 9.82022-02-04
A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands via uploading malicious files.
- CVE-2022-23346HIGHCVSS 8.8EG 8.82022-03-21
BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues.
- CVE-2022-23375HIGHCVSS 8.8EG 8.82022-02-19
WikiDocs version 0.1.18 has an authenticated remote code execution vulnerability. An attacker can upload a malicious file using the image upload form through index.php.
- CVE-2022-23390CRITICALCVSS 9.8EG 9.82022-02-14
An issue in the getType function of BBS Forum v5.3 and below allows attackers to upload arbitrary files.
- CVE-2022-2356HIGHCVSS 8.8EG 8.82022-08-08
The Frontend File Manager & Sharing WordPress plugin before 1.1.3 does not filter file extensions when letting users upload files on the server, which may lead to malicious code being uploaded.
- CVE-2022-23880CRITICALCVSS 9.8EG 9.82022-03-23
An arbitrary file upload vulnerability in the File Management function module of taoCMS v3.0.2 allows attackers to execute arbitrary code via a crafted PHP file.
- CVE-2022-23906HIGHCVSS 7.2EG 7.22022-02-28
CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability via the upload avatar function. This vulnerability is exploited via a crafted image file.
- CVE-2022-24136CRITICALCVSS 9.8EG 9.82022-03-31
Hospital Management System v1.0 is affected by an unrestricted upload of dangerous file type vulerability in treatmentrecord.php. To exploit, an attacker can upload any PHP file, and then execute it.
- CVE-2022-2418HIGHCVSS 8.0EG 8.02022-07-15
A vulnerability was found in URVE Web Manager. It has been classified as critical. This affects an unknown part of the file kreator.html5/img_upload.php. The manipulation leads to unrestricted upload. Access to the local network is require…
- CVE-2022-2419HIGHCVSS 8.0EG 8.02022-07-15
A vulnerability was found in URVE Web Manager. It has been declared as critical. This vulnerability affects unknown code of the file _internal/collector/upload.php. The manipulation leads to unrestricted upload. Access to the local network…
- CVE-2022-2420HIGHCVSS 8.0EG 8.02022-07-15
A vulnerability was found in URVE Web Manager. It has been rated as critical. This issue affects some unknown processing of the file _internal/uploader.php. The manipulation leads to unrestricted upload. The attack needs to be approached w…
- CVE-2022-24239CRITICALCVSS 9.8EG 9.82022-06-02
ACEweb Online Portal 3.5.065 was discovered to contain an unrestricted file upload vulnerability via attachments.awp.
- CVE-2022-24251HIGHCVSS 8.8EG 8.82022-03-01
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload function.
- CVE-2022-24252HIGHCVSS 8.8EG 8.82022-03-01
An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted file.
- CVE-2022-24253HIGHCVSS 8.8EG 8.82022-03-01
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet.
- CVE-2022-24254HIGHCVSS 8.8EG 8.82022-03-01
An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted ZIP file.
- CVE-2022-24262HIGHCVSS 8.8EG 7.82022-02-04
The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, allowing remote attackers to execute arbitrary commands via a crafted file in the web root.
- CVE-2022-24387CRITICALCVSS 9.1EG 7.22022-03-14
With administrator or admin privileges the application can be tricked into overwriting files in app_data/Config folder, e.g. the systemsettings.xml file. THis is possible in SmarterTrack v100.0.8019.14010
- CVE-2022-24553CRITICALCVSS 9.8EG 9.82022-02-21
An issue was found in Zfaka <= 1.4.5. The verification of the background file upload function check is not strict, resulting in remote command execution.
- CVE-2022-24581HIGHCVSS 7.5EG 7.52022-06-02
ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an external SMB share when uploading a file, an attacker can induce the victim server to disclose the username and password ha…
- CVE-2022-24651CRITICALCVSS 9.8EG 9.82022-03-10
sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in PHP code execution through /user/upload/upload.
- CVE-2022-24652CRITICALCVSS 9.8EG 9.82022-03-10
sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in php code execution in /admin/upload/upload.
- CVE-2022-24676HIGHCVSS 8.8EG 8.82022-02-09
update_code in Admin.php in HYBBS2 through 2.3.2 allows arbitrary file upload via a crafted ZIP archive.
- CVE-2022-24688HIGHCVSS 8.8EG 8.82022-07-18
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The Touch settings allow unrestricted file upload (and consequently Remote Code Execution) via PDF upload with PHP content and a .php extension. The attacker must hijack or o…
- CVE-2022-24749MEDIUMCVSS 6.1EG 6.12022-03-14
Sylius is an open source eCommerce platform. In versions prior to 1.9.10, 1.10.11, and 1.11.2, it is possible to upload an SVG file containing cross-site scripting (XSS) code in the admin panel. In order to perform a XSS attack, the file i…
- CVE-2022-24837MEDIUMCVSS 5.3EG 5.32022-04-11
HedgeDoc is an open-source, web-based, self-hosted, collaborative markdown editor. Images uploaded with HedgeDoc version 1.9.1 and later have an enumerable filename after the upload, resulting in potential information leakage of uploaded d…
- CVE-2022-24984CRITICALCVSS 9.8EG 9.82022-02-16
Forms generated by JQueryForm.com before 2022-02-05 (if file-upload capability is enabled) allow remote unauthenticated attackers to upload executable files and achieve remote code execution. This occurs because file-extension checks occur…
- CVE-2022-25016CRITICALCVSS 9.8EG 9.82022-03-02
Home Owners Collection Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /student_attendance/index.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP…
- CVE-2022-25115HIGHCVSS 7.8EG 7.82022-03-02
A remote code execution (RCE) vulnerability in the Avatar parameter under /admin/?page=user/manage_user of Home Owners Collection Management System v1.0 allows attackers to execute arbitrary code via a crafted PNG file.
- CVE-2022-25277HIGHCVSS 7.2EG 7.22023-04-26
Drupal core sanitizes filenames with dangerous extensions upon upload (reference: SA-CORE-2020-012) and strips leading and trailing dots from filenames to prevent uploading server configuration files (reference: SA-CORE-2019-010). However,…
- CVE-2022-25360HIGHCVSS 8.8EG 8.82022-02-24
WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to upload files to arbitrary locations. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x t…
- CVE-2022-25411CRITICALCVSS 9.8EG 9.82022-02-28
A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file.
- CVE-2022-25487CRITICALCVSS 9.8EG 9.82022-03-15
Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php.
- CVE-2022-25495CRITICALCVSS 9.8EG 9.82022-03-15
The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arbitrary code via a crafted PHP file.
- CVE-2022-25581HIGHCVSS 7.8EG 7.82022-03-18
Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload. This vulnerability allows attackers to execute code injection via a crafted .txt file.
- CVE-2022-25602HIGHCVSS 8.3EG 8.82022-03-18
Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Responsive Menu WordPress plugin (versions <= 4.1.7).
- CVE-2022-2594HIGHCVSS 8.8EG 8.82022-08-22
The Advanced Custom Fields WordPress plugin before 5.12.3, Advanced Custom Fields Pro WordPress plugin before 5.12.3 allows unauthenticated users to upload files allowed in a default WP configuration (so PHP is not possible) if there is a …
- CVE-2022-26149HIGHCVSS 7.2EG 7.22022-02-26
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator.
- CVE-2022-2647HIGHCVSS 7.3EG 9.82022-08-04
A vulnerability was found in jeecg-boot. It has been declared as critical. This vulnerability affects unknown code of the file /api/. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely.…
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →