XpressEngine vulnerable to Unrestricted Upload of File with Dangerous Type
Critical severity
GitHub Reviewed
Published
Jan 20, 2023
to the GitHub Advisory Database
•
Updated Feb 8, 2023
Description
Published by the National Vulnerability Database
Jan 20, 2023
Published to the GitHub Advisory Database
Jan 20, 2023
Reviewed
Feb 8, 2023
Last updated
Feb 8, 2023
When uploading an image file to a bulletin board developed with XpressEngine, a vulnerability in which an arbitrary file can be uploaded due to insufficient verification of the file. A remote attacker can use this vulnerability to execute arbitrary code on the server where the bulletin board is running.
References