CVE-2025-28168
MEDIUMMultiple File Upload 3.1.0 - Unrestricted Upload of File with Dangerous Type via Parameter Tampering
Title source: llmDescription
The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload. This occurs because file extension and size validations are enforced solely on the client side. An attacker can intercept the upload request and modify a parameter to bypass extension restrictions and upload arbitrary files. NOTE: this is a third-party component that is not supplied or supported by OutSystems.
References (2)
Core 2
Core References
Third Party Advisory
https://gist.github.com/IamLeandrooooo/01090be3023f5e7c7397bb9b1f5505b9
Scores
CVSS v3
6.4
EPSS
0.0028
EPSS Percentile
19.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-434
CWE-602
Status
published
Products (1)
multiple_file_upload_project/multiple_file_upload
3.1.0
Published
May 05, 2025
Tracked Since
Feb 18, 2026