JQuery File Upload Plugin Unauthenticated Arbitrary File Upload Vulnerability
Last Update Date:
24 Oct 2018 10:20
Release Date:
24 Oct 2018
5290
Views
RISK: Medium Risk
TYPE: Servers - Other Servers

A vulnerability was identified in in JQuery File Upload Plugin, a remote attacker could exploit this vulnerability to trigger remote code execution, disclose sensitive information and bypass security restriction on the targeted system.
Impact
- Remote Code Execution
- Security Restriction Bypass
- Information Disclosure
System / Technologies affected
- Version prior to 9.22.1
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix: https://github.com/blueimp/jQuery-File-Upload/blob/master/VULNERABILITIES.md#remote-code-execution-vulnerability-in-the-php-component
Vulnerability Identifier
Source
Related Link
Share with