Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-qwvp-g9j7-28f6: froxlor/froxlor vulnerable to Unrestricted Upload of File with Dangerous Type

Image files uploaded in froxlor/froxlor prior to 2.0.14 were not properly validated which could result in remote code execution via path manipulation.

ghsa
#git#rce#perl

froxlor/froxlor vulnerable to Unrestricted Upload of File with Dangerous Type

Critical severity GitHub Reviewed Published Apr 14, 2023 to the GitHub Advisory Database • Updated Apr 17, 2023

Related news

CVE-2023-2034: better validation for uploaded/imported image files · Froxlor/Froxlor@f36bc61

Unrestricted Upload of File with Dangerous Type in GitHub repository froxlor/froxlor prior to 2.0.14.