RSS   Vulnerabilities for 'Oneupuploaderbundle'   RSS

2020-02-05
 
CVE-2020-5237

CWE-22
 

 
oneup/uploader-bundle before 1.9.3 and 2.1.5, can be exploited to upload files to arbitrary folders on the filesystem. The assembly process can further be misused with some restrictions to delete and copy files to other locations. This is fixed in versions 1.9.3 and 2.1.5.

 


Copyright 2020, cxsecurity.com

 

Back to Top