CVE-2019-8293

CRITICAL WAF: Medium
CVSS 9.8 Published: 2019-12-23
CWE-434

Due to a logic error in the code, upload-image-with-ajax v1.0 allows arbitrary files to be uploaded to the web root allowing code execution.

WAF Coverage Analysis

Unrestricted File Upload Medium WAF Coverage

OWASP: A04:2021 Insecure Design

930xxx - Local File Inclusion

Affected Software

VendorProductVersion
abcprintfupload-image-with-ajax1.0

References

Back to CVE Database