CVE-2013-6234: Malicious File Upload
Published Nov 22, 2019
·Updated
Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, aka "XSS File Upload."
Affected Software
1 affected component
eng SpagoBI<4.1
Event History
Nov 22, 2019
CVE Published
via MITRE·06:46 PM
Data Sourced
via MITRE·06:46 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2013-6234.
2
What is the severity of CVE-2013-6234?
The severity of CVE-2013-6234 is high with a severity value of 8.
3
What is the affected software for CVE-2013-6234?
The affected software for CVE-2013-6234 is SpagoBI before version 4.1.
4
What is the CWE number for CVE-2013-6234?
The CWE number for CVE-2013-6234 is CWE-79 and CWE-434.
5
How can I fix the unrestricted file upload vulnerability in SpagoBI?
To fix the unrestricted file upload vulnerability in SpagoBI, you should update to version 4.1 or newer.