What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in wibergsweb CSV to html csv-to-html allows Upload a Web Shell to a Web Server.This issue affects CSV to html: from n/a through <= 3.26.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in wibergsweb CSV to html csv-to-html allows Upload a Web Shell to a Web Server.This issue affects CSV to html: from n/a through <= 3.26.
Explanation of Vulnerability in Simple Terms
CSV to HTML versions 3.26 and earlier allow authenticated users to upload files without proper validation. An attacker with low-level access can upload malicious files that may lead to code execution or site compromise. The vulnerability affects the entire system due to scope change, making it a critical risk for any site running this component.
What an attacker can do
Upload malicious files to the server and execute code or compromise the site.
Potential impact on your site
Any authenticated user can upload files and potentially take over your site or access sensitive data.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities