Unrestricted Upload of File with Dangerous Type Affecting fineuploader/php-traditional-server package, versions >=0.0.0
Snyk CVSS
Attack Complexity
Low
Confidentiality
High
Integrity
High
Availability
High
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.54% (78th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PHP-FINEUPLOADERPHPTRADITIONALSERVER-6673806
- published 25 Apr 2024
- disclosed 14 May 2022
- credit Larry W. Cashdollar
Introduced: 14 May 2022
CVE-2018-9209 Open this link in a new tabHow to fix?
There is no fixed version for fineuploader/php-traditional-server
.
Overview
fineuploader/php-traditional-server is an endpoint handler for Fine Uploader's traditional server requests.
Affected versions of this package are vulnerable to Unrestricted Upload of File with Dangerous Type due to improper validation of file types in endpoint.php
. An attacker can upload arbitrary files to the server by crafting a request that bypasses the upload restrictions.