What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in Tumult Inc. Tumult Hype Animations.This issue affects Tumult Hype Animations: from n/a through 1.9.12.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in Tumult Inc. Tumult Hype Animations.This issue affects Tumult Hype Animations: from n/a through 1.9.12.
Explanation of Vulnerability in Simple Terms
Tumult Hype Animations versions up to 1.9.12 allow authenticated administrators to upload files without proper validation. An attacker with high-level privileges can upload malicious files that may affect confidentiality, integrity, and availability of the system. The vulnerability has a network attack vector and does not require user interaction.
What an attacker can do
Upload malicious files to the server and potentially execute code or compromise system integrity.
Potential impact on your site
An admin account compromise could lead to unauthorized file uploads, data theft, or site takeover.
Conditions required to exploit
Attacker must have high-level administrative privileges and network access to the application.
Key dates
External resources
Related vulnerabilities