wangl1989 mysiteforme
cpe:2.3:a:wangl1989:mysiteforme:*:*:*:*:*:*:*
- 1.0
A critical vulnerability allowing arbitrary file upload has been identified in Wangl1989 MySiteForMe version 1.0. The issue resides in the LocalUploadServiceImpl file, where the upload function fails to properly validate file types. This flaw enables remote attackers to upload malicious JSP or HTML files, potentially leading to the execution of harmful scripts on the server.
Exploitation of this vulnerability allows for arbitrary file upload, with the potential for uploaded files to be executed as scripts, depending on the server configuration.
To reproduce this vulnerability, access the file upload interface and upload an image file. After the upload, intercept the request and change the file extension to JSP or HTML. Once the modified file is uploaded, it can be accessed through the server's static upload directory, where it will be executed as a script.
Users are advised to update to the latest version of MySiteForMe, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.