CVE-2020-29441

An issue was discovered in the Upload Widget in OutSystems Platform 10 before 10.0.1019.0. An unauthenticated attacker can upload arbitrary files. In some cases, this attack may consume the available database space (Denial of Service), corrupt legitimate data if files are being processed asynchronously, or deny access to legitimate uploaded files.
Configurations

Configuration 1 (hide)

cpe:2.3:a:outsystems:outsystems:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:24

Type Values Removed Values Added
CVSS v2 : 6.4
v3 : 6.5
v2 : 6.4
v3 : 7.2
References () https://success.outsystems.com/Support/Security/Vulnerabilities/Vulnerability_RPD-4310 - Vendor Advisory () https://success.outsystems.com/Support/Security/Vulnerabilities/Vulnerability_RPD-4310 - Vendor Advisory

Information

Published : 2020-11-30 22:15

Updated : 2024-11-21 05:24


NVD link : CVE-2020-29441

Mitre link : CVE-2020-29441

CVE.ORG link : CVE-2020-29441


JSON object : View

Products Affected

outsystems

  • outsystems
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type