CVE-2020-36485

Portable Ltd Playable v9.18 was discovered to contain an arbitrary file upload vulnerability in the filename parameter of the upload module. This vulnerability allows attackers to execute arbitrary code via a crafted JPEG file.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:madeportable:playable:9.18:*:*:*:*:iphone_os:*:*

History

21 Nov 2024, 05:29

Type Values Removed Values Added
References () https://www.vulnerability-lab.com/get_content.php?id=2198 - Exploit, Third Party Advisory () https://www.vulnerability-lab.com/get_content.php?id=2198 - Exploit, Third Party Advisory

28 Oct 2021, 17:06

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 4.6
v3 : 7.8
CPE cpe:2.3:a:madeportable:playable:9.18:*:*:*:*:iphone_os:*:*
References (MISC) https://www.vulnerability-lab.com/get_content.php?id=2198 - (MISC) https://www.vulnerability-lab.com/get_content.php?id=2198 - Exploit, Third Party Advisory
CWE CWE-434

22 Oct 2021, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-10-22 20:15

Updated : 2024-11-21 05:29


NVD link : CVE-2020-36485

Mitre link : CVE-2020-36485

CVE.ORG link : CVE-2020-36485


JSON object : View

Products Affected

madeportable

  • playable
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type