CVE-2021-46078

CVSS v3 Score
4.8
Medium
CVSS v2 Score
3.5
Low

Vulnerability Description

An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can upload malicious files leading to a Stored Cross-Site Scripting vulnerability.

CVSS:4.8(Medium)

Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.2.11.

CVSS:4.8(Medium)

An arbitrary file upload vulnerability in Halo up to v1.6.1 allows attackers to execute arbitrary code via a crafted .md file.

CVSS:4.8(Medium)

Gradio v3.27.0 was discovered to contain an arbitrary file upload vulnerability via the /upload interface.

CVSS:4.8(Medium)

The Zarinpal Paid Download WordPress plugin through 2.3 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they sh...

CVSS:4.8(Medium)

SAP NetWeaver AS JAVA (User Admin Application) is vulnerable to stored cross site scripting vulnerability. An attacker posing as an admin can upload a photo with malicious JS content. When a victim vi...

CVSS:4.7(Medium)

Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2.