An issue was discovered in the Upload Widget in OutSystems Platform 10 before 10.0.1019.0. An unauthenticated attacker can upload arbitrary files. In some cases, this attack may consume the available database space (Denial of Service), corrupt legitimate data if files are being processed asynchronously, or deny access to legitimate uploaded files.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-11-30T21:36:51
Updated: 2024-08-04T16:55:09.667Z
Reserved: 2020-11-30T00:00:00
Link: CVE-2020-29441
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-11-30T22:15:11.073
Modified: 2024-11-21T05:24:00.680
Link: CVE-2020-29441
Redhat
No data.