The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload. This occurs because file extension and size validations are enforced solely on the client side. An attacker can intercept the upload request and modify a parameter to bypass extension restrictions and upload arbitrary files. NOTE: this is a third-party component that is not supplied or supported by OutSystems.
References
Link | Resource |
---|---|
https://gist.github.com/IamLeandrooooo/01090be3023f5e7c7397bb9b1f5505b9 | Third Party Advisory |
https://www.outsystems.com/forge/component-overview/200/multiple-file-upload-o11 | Product |
Configurations
Configuration 1 (hide)
|
History
17 Jun 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
First Time |
Multiple File Upload Project multiple File Upload
Multiple File Upload Project |
|
References | () https://gist.github.com/IamLeandrooooo/01090be3023f5e7c7397bb9b1f5505b9 - Third Party Advisory | |
References | () https://www.outsystems.com/forge/component-overview/200/multiple-file-upload-o11 - Product | |
CPE | cpe:2.3:a:multiple_file_upload_project:multiple_file_upload:3.1.0:*:*:*:*:outsystems:*:* |
08 May 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.4 |
CWE | CWE-602 | |
Summary | (en) The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload. This occurs because file extension and size validations are enforced solely on the client side. An attacker can intercept the upload request and modify a parameter to bypass extension restrictions and upload arbitrary files. NOTE: this is a third-party component that is not supplied or supported by OutSystems. |
07 May 2025, 19:16
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
CWE | CWE-434 |
05 May 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-05 14:15
Updated : 2025-06-17 14:15
NVD link : CVE-2025-28168
Mitre link : CVE-2025-28168
CVE.ORG link : CVE-2025-28168
JSON object : View
Products Affected
multiple_file_upload_project
- multiple_file_upload