What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in UjW0L Image Classify image-classify allows Upload a Web Shell to a Web Server.This issue affects Image Classify: from n/a through <= 1.0.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in UjW0L Image Classify image-classify allows Upload a Web Shell to a Web Server.This issue affects Image Classify: from n/a through <= 1.0.0.
Explanation of Vulnerability in Simple Terms
Image Classify versions 1.0.0 and earlier contain an unrestricted file upload vulnerability. An attacker can upload arbitrary files to the server without authentication or user interaction. This allows execution of malicious code, data theft, and service disruption. All users should update immediately.
What an attacker can do
Upload and execute arbitrary files on the server without authentication.
Potential impact on your site
Complete compromise of the server: attackers can run code, steal data, modify content, and take the site offline.
Conditions required to exploit
Network access to the vulnerable application; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities