CVE-2021-23562: Arbitrary File Upload
This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a user to upload this kind of file.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-23562?
CVE-2021-23562 is a vulnerability that affects the plupload package versions before 2.3.9.
What is the severity of CVE-2021-23562?
The severity of CVE-2021-23562 is rated as high with a CVSS score of 8.8.
How does CVE-2021-23562 impact plupload?
CVE-2021-23562 allows an attacker to upload and execute JavaScript code by tricking a user into uploading a file with a malicious filename.
How can I fix CVE-2021-23562?
To fix CVE-2021-23562, upgrade your plupload package to version 2.3.9 or newer.
Is there any additional information about CVE-2021-23562?
You can find additional information about CVE-2021-23562 at the following references: [1](https://github.com/moxiecode/plupload/blob/master/js/jquery.plupload.queue/jquery.plupload.queue.js%23L226), [2](https://github.com/moxiecode/plupload/commit/d12175d4b5fa799b994ee1bb17bfbeec55b386fb), [3](https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-2306665).