Vulnerabilities/

File Upload Functionality

Severity:
Informational

Description

The <input> element with type="file" enables users to select and upload files from their device storage to a remote server. However, unrestricted file upload functionality can introduce an arbitrary file upload vulnerability, allowing malicious users to upload and potentially execute any file on the server.

Recommendation

To mitigate this risk:

Related Issues

Tags:
Risk
File Upload
Arbitrary File Upload
Anything's wrong? Let us know Last updated on May 13, 2024

Use SmartScanner Free version to test for this issue

Download