The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload. This occurs because file extension and size validations are enforced solely on the client side. An attacker can intercept the upload request and modify a parameter to bypass extension restrictions and upload arbitrary files. NOTE: this is a third-party component that is not supplied or supported by OutSystems.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://gist.github.com/IamLeandrooooo/01090be3023f5e7c7397bb9b1f5505b9 | Third Party Advisory |
| https://www.outsystems.com/forge/component-overview/200/multiple-file-upload-o11 | Product |
Configurations
Configuration 1 (hide)
|
History
17 Jun 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:multiple_file_upload_project:multiple_file_upload:3.1.0:*:*:*:*:outsystems:*:* | |
| First Time |
Multiple File Upload Project
Multiple File Upload Project multiple File Upload |
|
| References | () https://www.outsystems.com/forge/component-overview/200/multiple-file-upload-o11 - Product | |
| References | () https://gist.github.com/IamLeandrooooo/01090be3023f5e7c7397bb9b1f5505b9 - Third Party Advisory |
08 May 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload. This occurs because file extension and size validations are enforced solely on the client side. An attacker can intercept the upload request and modify a parameter to bypass extension restrictions and upload arbitrary files. NOTE: this is a third-party component that is not supplied or supported by OutSystems. |
05 May 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-05-05 14:15
Updated : 2025-06-17 14:15
NVD link : CVE-2025-28168
Mitre link : CVE-2025-28168
JSON object : View
Products Affected
multiple_file_upload_project
- multiple_file_upload
CWE
No CWE.
