SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-29441

An unauthenticated attacker can upload arbitrary files.

MEDIUM 6.5EPSS 0.95%

Does this matter?

Lower severity and a low EPSS score (0.95%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in the Upload Widget in OutSystems Platform 10 before 10.0.1019.0. An unauthenticated attacker can upload arbitrary files. In some cases, this attack may consume the available database space (Denial of Service), corrupt legitimate data if files are being processed asynchronously, or deny access to legitimate uploaded files.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
EPSS
0.95% probability · 59th percentile
CISA KEV
Not listed
Weakness
CWE-434
Affected
outsystems/outsystems
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.