PT-2021-15538 · Plupload · Plupload

Michele Di Stefano

·

Published

2021-12-03

·

Updated

2021-12-16

·

CVE-2021-23562

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions plupload versions prior to 2.3.9
Description The issue allows an attacker to upload a file with a name containing JavaScript code, which could then be executed. This would require the attacker to trick a user into uploading such a file. There is no information provided about the estimated number of potentially affected devices or real-world incidents where this issue was exploited.
Recommendations For versions prior to 2.3.9, update to version 2.3.9 or later to resolve the issue. As a temporary workaround, consider restricting file uploads to prevent the execution of JavaScript code until a patch is applied. Avoid allowing users to upload files with names containing JavaScript code in the affected plupload package.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23562
GHSA-RP2C-JRGP-CVR8
SNYK-JAVA-ORGWEBJARS-2306665
SNYK-JAVA-ORGWEBJARSBOWER-2306663
SNYK-JAVA-ORGWEBJARSBOWERGITHUBMOXIECODE-2306664
SNYK-JS-PLUPLOAD-1583909

Affected Products

Plupload