Unrestricted File Upload Vulnerability in Novel-Plus by Java2NB
CVE-2021-42967
9.8CRITICAL
What is CVE-2021-42967?
A vulnerability in the FileController.java of the Novel-Plus application permits unrestricted file uploads. This flaw enables an attacker to upload potentially harmful JSP files, compromising the integrity of the application and causing security risks. Proper validations and restrictions on file types and upload permissions are essential to mitigate this vulnerability.