Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x9rr-xwxc-jcjf

Опубликовано: 05 мая 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Outsystems Multiple File Upload < 3.1.0 is vulnerable to Unrestricted File Upload. The vulnerability is because file extension and size validations are enforced solely on the client side. An attacker can intercept the upload request and modify the parameter to bypass extension restrictions and upload arbitrary files.

Outsystems Multiple File Upload < 3.1.0 is vulnerable to Unrestricted File Upload. The vulnerability is because file extension and size validations are enforced solely on the client side. An attacker can intercept the upload request and modify the parameter to bypass extension restrictions and upload arbitrary files.

EPSS

Процентиль: 15%
0.00047
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-434
CWE-602

Связанные уязвимости

CVSS3: 6.4
nvd
9 месяцев назад

The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload. This occurs because file extension and size validations are enforced solely on the client side. An attacker can intercept the upload request and modify a parameter to bypass extension restrictions and upload arbitrary files. NOTE: this is a third-party component that is not supplied or supported by OutSystems.

EPSS

Процентиль: 15%
0.00047
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-434
CWE-602