Wangl1989 MySiteForMe Unrestricted File Upload Vulnerability in LocalUploadServiceImpl

Vulnerability

A critical vulnerability allowing arbitrary file upload has been identified in Wangl1989 MySiteForMe version 1.0. The issue resides in the LocalUploadServiceImpl file, where the upload function fails to properly validate file types. This flaw enables remote attackers to upload malicious JSP or HTML files, potentially leading to the execution of harmful scripts on the server.

Impact

Exploitation of this vulnerability allows for arbitrary file upload, with the potential for uploaded files to be executed as scripts, depending on the server configuration.

Reproduction

To reproduce this vulnerability, access the file upload interface and upload an image file. After the upload, intercept the request and change the file extension to JSP or HTML. Once the modified file is uploaded, it can be accessed through the server's static upload directory, where it will be executed as a script.

Remediation

Users are advised to update to the latest version of MySiteForMe, where this vulnerability has been addressed.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.2
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.