What the vulnerability does
01Description
Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
Explanation of Vulnerability in Simple Terms
MapSVG versions up to 8.14.0 contain an unrestricted file upload vulnerability. An authenticated administrator can upload files without proper validation, potentially allowing them to upload malicious files to the server. This could lead to unauthorized access, data theft, or site compromise. Update to a version newer than 8.14.0 to resolve this issue.
What an attacker can do
Upload arbitrary files to the server and execute malicious code.
Potential impact on your site
An admin account compromise could allow file uploads leading to full site takeover or data breach.
Conditions required to exploit
Attacker must have administrator-level access to MapSVG.
Key dates
External resources
Related vulnerabilities