CVE-2025-28168: Critical severity Outsystems Multiple File Upload add-on vulnerability
The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload. This occurs because file extension and size validations are enforced solely on the client side. An attacker can intercept the upload request and modify a parameter to bypass extension restrictions and upload arbitrary files. NOTE: this is a third-party component that is not supplied or supported by OutSystems.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-28168?
The severity of CVE-2025-28168 is considered critical due to the potential for attackers to upload malicious files.
How do I fix CVE-2025-28168?
To fix CVE-2025-28168, update to Outsystems Multiple File Upload version 3.1.0 or later, which addresses the unrestricted file upload vulnerability.
What are the risks associated with CVE-2025-28168?
The risks associated with CVE-2025-28168 include potential remote code execution and data breaches due to unrestricted file uploads.
Who is affected by CVE-2025-28168?
Users of Outsystems Multiple File Upload versions prior to 3.1.0 are affected by CVE-2025-28168.
What type of vulnerability is CVE-2025-28168?
CVE-2025-28168 is categorized as an Unrestricted File Upload vulnerability.