{"id":"CVE-2018-9206","details":"Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload \u003c= v9.22.0","aliases":["GHSA-4cj8-g9cp-v5wr"],"modified":"2026-08-14T09:05:27.922387Z","published":"2018-10-11T15:29:00.640Z","references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/105679"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/106629"},{"type":"REPORT","url":"https://github.com/psolom/RichFilemanager/issues/354"},{"type":"REPORT","url":"https://github.com/psolom/RichFilemanager/issues/412"},{"type":"FIX","url":"https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html"},{"type":"EVIDENCE","url":"http://www.vapidlabs.com/advisory.php?v=204"},{"type":"EVIDENCE","url":"https://wpvulndb.com/vulnerabilities/9136"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/45790/"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/46182/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/blueimp/jquery-file-upload","events":[{"introduced":"0"},{"last_affected":"39607fdaaba0dc11ba8c116ac2968e28e796f153"}],"database_specific":{"cpe":"cpe:2.3:a:jquery_file_upload_project:jquery_file_upload:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"9.22.0"}],"source":"CPE_RANGE"}}],"versions":["v9.22.0","v9.21.0","v9.20.0","v9.19.3","v9.19.2","v9.19.1","v9.19.0","v9.18.0","v9.17.0","v9.16.0","v9.15.0","v9.14.2","v9.14.1","v9.14.0","v9.13.1","v9.13.0","v9.12.6","9.12.5","9.12.4","9.12.3","9.12.2","9.12.1","9.12.0","9.11.2","9.11.1","9.11.0","9.10.7","9.10.6","9.10.5","9.10.4","9.10.3","9.10.2","9.10.1","9.10.0","9.9.4","9.9.3","9.9.2","9.9.1","9.9.0","9.8.1","9.8.0","9.7.2","9.7.1","9.7.0","9.6.0","9.5.8","9.5.7","9.5.6","9.5.5","9.5.4","9.5.3","9.5.2","9.5.1","9.5.0","9.4.2","9.4.1","9.4.0","9.3.0","9.2.1","9.2.0","9.1.0","9.0.2","9.0.1","9.0.0","8.9.0","8.8.7","8.8.5","8.8.4","8.8.2","8.7.1","8.7.0","8.6.1","8.6.0","8.5.1","8.5.0","8.4.3","8.4.2","8.4.1","8.4.0","8.3.2","8.3.1","8.3.0","8.2.1","8.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-9206.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}