CVE-2021-23562
MEDIUM EXPLOITEDTiny Plupload < 2.3.9 - Unrestricted File Upload
Title source: ruleDescription
This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a user to upload this kind of file.
References (6)
Core 6
Core References
Patch, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-JS-PLUPLOAD-1583909
Patch, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-2306663
Patch, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBMOXIECODE-2306664
Patch, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-2306665
Broken Link x_refsource_misc
https://github.com/moxiecode/plupload/blob/master/js/jquery.plupload.queue/jquery.plupload.queue.js%23L226
Patch, Third Party Advisory x_refsource_misc
https://github.com/moxiecode/plupload/commit/d12175d4b5fa799b994ee1bb17bfbeec55b386fb
Scores
CVSS v3
4.2
EPSS
0.0050
EPSS Percentile
66.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Details
VulnCheck KEV
2013-02-18
CWE
CWE-434
Status
published
Products (2)
npm/plupload
0 - 2.3.9npm
tiny/plupload
< 2.3.9
Published
Dec 03, 2021
Tracked Since
Feb 18, 2026