osuuu LightPicture
cpe:2.3:a:osuuu:lightpicture:*:*:*:*:*:*:*
- 1.2.2
A critical unrestricted file upload vulnerability has been identified in osuuu LightPicture version 1.2.2. The issue arises in the file upload function of the Api.php controller, where improper validation allows for unrestricted file uploads. This vulnerability can be exploited remotely.
Exploitation of this vulnerability allows for unrestricted file uploads, which could lead to various consequences depending on the application's file handling and execution capabilities.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.