Withdrawn Advisory: Unrestricted File Upload affecting automad
Moderate severity
GitHub Reviewed
Published
Dec 21, 2023
to the GitHub Advisory Database
•
Updated Aug 20, 2024
Withdrawn
This advisory was withdrawn on Aug 20, 2024
Description
Published by the National Vulnerability Database
Dec 21, 2023
Published to the GitHub Advisory Database
Dec 21, 2023
Reviewed
Dec 29, 2023
Withdrawn
Aug 20, 2024
Last updated
Aug 20, 2024
Withdrawn Advisory
This advisory has been withdrawn because JavaScript execution is the intended functionality of automad. This link is maintained to preserve external references.
Original Description
A vulnerability was found in automad up to 1.10.9. This affects the function upload of the file
FileCollectionController.php
of the componentContent Type Handler
. The manipulation leads to unrestricted upload. The attack may be launched remotely and an exploit has been disclosed publicly.References