PT-2026-29508 · Harvard University · Iqss Dataverse
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Harvard University IQSS Dataverse versions up to 6.8
Description
A flaw exists in Harvard University IQSS Dataverse that allows for unrestricted file upload through manipulation of the
uploadLogo argument in the /ThemeAndWidgets.xhtml file within the Theme Customization component. This issue is publicly exploitable.Recommendations
Upgrade to version 6.10 or later.
Exploit
Fix
Improper Access Control
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Iqss Dataverse