Improper Input Validation Affecting verot/class.upload.php package, versions >=0.0.0


Severity

Recommended
0.0
critical
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.05% (21st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improper Input Validation vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-VEROTCLASSUPLOADPHP-6144804
  • published5 Jan 2024
  • disclosed4 Jan 2024
  • creditUnknown

Introduced: 4 Jan 2024

CVE-2023-6551  (opens in a new tab)
CWE-20  (opens in a new tab)

How to fix?

There is no fixed version for verot/class.upload.php.

Overview

verot/class.upload.php is a PHP class that can be used to upload files and manipulate images very easily.

Affected versions of this package are vulnerable to Improper Input Validation when the default configuration is used. An attacker can inject malicious scripts that may be executed in the context of the user's browser by uploading specially crafted files.

Workaround

To mitigate this vulnerability it is recommended to use extension whitelisting accompanied by forcing the server to always provide content-type based on the file extension. The README has been updated to include these guidelines.

References

CVSS Scores

version 3.1