Description
Multiple vendor applications utilize Uploadify. Uploadify is a jQuery plugin that integrates a fully-customizable multiple file upload utility on your website. Uploadify contains functionality to handle file uploads. A remote attacker could use this functionality to upload malicous executable files on the system. To test file upload capabilities, Acunetix created a file named acunetix-uploadify-test.php in the server document root.
Remediation
It is recommended to replace the Uploadify script with a script that is more secure.
References
Related Vulnerabilities
MyBB Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9410)
Magento Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-7874)
ownCloud Exposure of Resource to Wrong Sphere Vulnerability (CVE-2022-31649)
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-20100)