Description
This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a user to upload this kind of file.
Recommendation
Update the plupload package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.3.9
- Patched version(s): 2.3.9
References
- GHSA-rp2c-jrgp-cvr8
- snyk.io
- CVE-2021-23562
- CWE-434
- CWE-75
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A4
- OWASP 2021-A6
Related Issues
- Risk of code injection - CVE-2021-21278
- Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability - CVE-2026-41265
- Script injection - @backstage/plugin-techdocs - CVE-2021-32661
- Code Injection in cryo - CVE-2018-3784
You might also like:
- Tags:
- npm
- plupload
Anything's wrong? Let us know Last updated on February 01, 2023


