vendor:
Hyip Rio
by:
CraCkEr
5.4
CVSS
MEDIUM
Arbitrary File Upload
434
CWE
Product Name: Hyip Rio
Affected Version From: 2.1
Affected Version To: 2.1
Patch Exists: NO
Related CWE: CVE-2023-4382
CPE: tdevs/hyip_rio/2.1
Platforms Tested: Windows 10 Pro
2023
Hyip Rio 2.1 – Arbitrary File Upload
Allows Attacker to upload malicious files onto the server, such as Stored XSS
Mitigation:
Implement proper file validation and sanitization techniques to prevent arbitrary file uploads. Additionally, ensure that uploaded files are stored in a secure location and not accessible directly from the web.