PT-2026-29508 · Harvard University · Iqss Dataverse
Justf0Rfun
+1
·
Published
2026-04-01
·
Updated
2026-04-01
·
CVE-2026-1879
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Harvard University IQSS Dataverse versions up to 6.8
Description
A flaw exists in Harvard University IQSS Dataverse that allows for unrestricted file upload through manipulation of the
uploadLogo argument in the /ThemeAndWidgets.xhtml file within the Theme Customization component. This issue is publicly exploitable.Recommendations
Upgrade to version 6.10 or later.
Exploit
Fix
Unrestricted File Upload
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Iqss Dataverse