This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a user to upload this kind of file.
References
Configurations
History
No history.
Information
Published : 2021-12-03 20:15
Updated : 2024-11-21 05:51
NVD link : CVE-2021-23562
Mitre link : CVE-2021-23562
CVE.ORG link : CVE-2021-23562
JSON object : View
Products Affected
tiny
- plupload
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type