Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:32963
HistoryNov 15, 2021 - 2:30 a.m.

Unrestricted File Upload

2021-11-1502:30:35
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
file upload
privilege escalation
phishing page
administrator credentials

EPSS

0.001

Percentile

29.8%

ssddanbrown/bookstack allows unrestricted file upload. Lack of checking uploaded file type and size allows an authenticated user with privilege to create role to upload any type of file, allowing upload of phishing page and get administrators credentials.

EPSS

0.001

Percentile

29.8%