craftcms/cms is vulnerable to Unrestricted Upload of File with Dangerous Type
21
Low Risk
Affected versions of this package are vulnerable to arbitrary file upload. Even when an upload is explicitly disallowed and the system correctly reports that the file should not be accepted, the file is still written to the temporary directory (storage/runtime/temp). This allows an attacker to place unexpected or malicious files on the server, potentially enabling further exploitation depending on server configuration and how temporary files are handled.
You are affected if you are using a version that falls within the vulnerable range.
craftcms/cms is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 3.0.0 - 4.16.15 and 5.0.0 - 5.8.19.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant