Releases5
Frequency8 months 4 days
Last Release
Stars40
PHP backend for resumable.js

CVE History

CVEPublishedCVSS v3CVSS v2
8.1 HIGH

resumable.php (aka PHP backend for resumable.js) 0.1.4 before 3c6dbf5 allows arbitrary file upload anywhere in the filesystem via ../ in multipart/form-data content to upload.php. (File overwrite hasn't been possible with the code available in GitHub in recent years, however.)