Vulnerabilities/

File Upload Functionality

Impact: Informational

Description

The <input> element with type="file" enables users to select and upload files from their device storage to a remote server. However, unrestricted file upload functionality can introduce an arbitrary file upload vulnerability, allowing malicious users to upload and potentially execute any file on the server.

Recommendation

To mitigate this risk:

Last updated on May 13, 2024

Use SmartScanner Free version to test for this issue

Download