The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload. This occurs because file extension and size validations are enforced solely on the client side. An attacker can intercept the upload request and modify a parameter to bypass extension restrictions and upload arbitrary files. NOTE: this is a third-party component that is not supplied or supported by OutSystems.
                
            References
                    | Link | Resource | 
|---|---|
| https://gist.github.com/IamLeandrooooo/01090be3023f5e7c7397bb9b1f5505b9 | Third Party Advisory | 
| https://www.outsystems.com/forge/component-overview/200/multiple-file-upload-o11 | Product | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    30 Sep 2025, 17:01
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-434 | 
26 Aug 2025, 20:15
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | 
17 Jun 2025, 14:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-05-05 14:15
Updated : 2025-09-30 17:01
NVD link : CVE-2025-28168
Mitre link : CVE-2025-28168
CVE.ORG link : CVE-2025-28168
JSON object : View
Products Affected
                multiple_file_upload_project
- multiple_file_upload
