What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in Zachary Segal CataBlog.This issue affects CataBlog: from n/a through 1.7.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in Zachary Segal CataBlog.This issue affects CataBlog: from n/a through 1.7.0.
Explanation of Vulnerability in Simple Terms
CataBlog versions up to 1.7.0 allow authenticated administrators to upload files without proper validation. An attacker with admin privileges can upload malicious files that may affect the confidentiality, integrity, and availability of the site and potentially other systems. The vulnerability requires high-level access but has broad impact due to changed scope.
What an attacker can do
Upload malicious files to the site with admin access, potentially compromising the site and connected systems.
Potential impact on your site
A compromised admin account can upload files that damage site integrity, expose data, or disrupt service.
Conditions required to exploit
Attacker must have administrator-level privileges on the CataBlog installation.
Key dates
External resources
Related vulnerabilities