10.32.0
6 years ago
1 years ago
Known vulnerabilities in the org.webjars.bowergithub.blueimp:jquery-file-upload package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the How to fix Cross-site Scripting (XSS)? There is no fixed version for | [0,) |
jquery-file-upload provides Multiple file Uploads with progress bar. Affected versions of this package contain demo code which is vulnerable to Arbitrary Code Execution due to allowing the upload of arbitrary files. It did not require any validation to upload files to the server. Using the How to fix Arbitrary Code Execution? There is no fix version for | (,) |