CVE-2021-23562

MEDIUM EXPLOITED

Tiny Plupload < 2.3.9 - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a user to upload this kind of file.

References (6)

Core 6

Scores

CVSS v3 4.2
EPSS 0.0050
EPSS Percentile 66.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

Details

VulnCheck KEV 2013-02-18
CWE
CWE-434
Status published
Products (2)
npm/plupload 0 - 2.3.9npm
tiny/plupload < 2.3.9
Published Dec 03, 2021
Tracked Since Feb 18, 2026