Skip to content

jQuery File Upload Plugin Unrestricted file upload vulnerability

High severity GitHub Reviewed Published May 17, 2022 to the GitHub Advisory Database • Updated Apr 25, 2024

Package

composer blueimp/jquery-file-upload (Composer)

Affected versions

= 6.4.4

Patched versions

None

Description

Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by uploading a PHP file with an PHP extension, then accessing it via a direct request to the file in files/, as exploited in the wild in October 2014.

References

Published by the National Vulnerability Database Feb 8, 2020
Published to the GitHub Advisory Database May 17, 2022
Reviewed Apr 25, 2024
Last updated Apr 25, 2024

Severity

High

EPSS score

79.163%
(99th percentile)

Weaknesses

CVE ID

CVE-2014-8739

GHSA ID

GHSA-wxg6-f773-g2f7

Source code

No known source code
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.