What the vulnerability does
01Description
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
Explanation of Vulnerability in Simple Terms
Type Hub versions up to 2.0.6 allow unauthenticated attackers to upload files of dangerous types without restriction. An attacker can upload executable code or malicious files directly to the server over the network. This vulnerability affects the entire system and can lead to complete compromise, including data theft, site defacement, and service disruption.
What an attacker can do
Upload and execute malicious files on the server without authentication.
Potential impact on your site
Complete system compromise: attackers can run code, steal data, deface content, or take the site offline.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities