Web / CMS
Authentication & Access Bypass
Drag and Drop Multiple File Upload < 1.3.6.5 - File Upload Size Limit Bypass
Drag and Drop Multiple File Upload < 1.3.6.5 – File Upload Size Limit Bypass The plugin does not properly check for the upload size limit set in forms, taking the value from user input sent when…
.png)
Overview
Drag and Drop Multiple File Upload < 1.3.6.5 – File Upload Size Limit Bypass
The plugin does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form. As a result, attackers could control the file length limit and bypass the limit set by admins in the contact form.
Vulnerability details
Drag and Drop Multiple File Upload < 1.3.6.5 – File Upload Size Limit Bypass The plugin does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form.
Disclosure timeline
2022-08-26 Reported On
2022-09-23 Made Public On
2022-09-23 Fixed On
References
Credits
Sanjay Das
















