First published: Fri Dec 03 2021(Updated: )
This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a user to upload this kind of file.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Tiny Plupload | <2.3.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23562 is a vulnerability that affects the plupload package versions before 2.3.9.
The severity of CVE-2021-23562 is rated as high with a CVSS score of 8.8.
CVE-2021-23562 allows an attacker to upload and execute JavaScript code by tricking a user into uploading a file with a malicious filename.
To fix CVE-2021-23562, upgrade your plupload package to version 2.3.9 or newer.
You can find additional information about CVE-2021-23562 at the following references: [1](https://github.com/moxiecode/plupload/blob/master/js/jquery.plupload.queue/jquery.plupload.queue.js%23L226), [2](https://github.com/moxiecode/plupload/commit/d12175d4b5fa799b994ee1bb17bfbeec55b386fb), [3](https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-2306665).