Vulnerabilities/

VvvebJs Arbitrary File Upload vulnerability

Severity:
Medium

Description

Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and obtain sensitive information via the sanitizeFileName parameter in save.php.

Recommendation

Update the vvvebJs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
vvvebJs
Anything's wrong? Let us know Last updated on August 02, 2024

This issue is available in SmartScanner Professional

See Pricing