CVE-2020-36485

Portable Ltd Playable v9.18 was discovered to contain an arbitrary file upload vulnerability in the filename parameter of the upload module. This vulnerability allows attackers to execute arbitrary code via a crafted JPEG file.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:madeportable:playable:9.18:*:*:*:*:iphone_os:*:*

History

21 Nov 2024, 05:29

Type Values Removed Values Added
References () https://www.vulnerability-lab.com/get_content.php?id=2198 - Exploit, Third Party Advisory () https://www.vulnerability-lab.com/get_content.php?id=2198 - Exploit, Third Party Advisory

Information

Published : 2021-10-22 20:15

Updated : 2024-11-21 05:29


NVD link : CVE-2020-36485

Mitre link : CVE-2020-36485

CVE.ORG link : CVE-2020-36485


JSON object : View

Products Affected

madeportable

  • playable
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type