{"id":"CVE-2020-5237","details":"Multiple relative path traversal vulnerabilities in the oneup/uploader-bundle before 1.9.3 and 2.1.5 allow remote attackers to upload, copy, and modify files on the filesystem (potentially leading to arbitrary code execution) via the (1) filename parameter to BlueimpController.php; the (2) dzchunkindex, (3) dzuuid, or (4) filename parameter to DropzoneController.php; the (5) qqpartindex, (6) qqfilename, or (7) qquuid parameter to FineUploaderController.php; the (8) x-file-id or (9) x-file-name parameter to MooUploadController.php; or the (10) name or (11) chunk parameter to PluploadController.php. This is fixed in versions 1.9.3 and 2.1.5.","aliases":["GHSA-x8wj-6m73-gfqp"],"modified":"2026-07-09T00:37:46.753717Z","published":"2020-02-05T14:15:11.527Z","references":[{"type":"ADVISORY","url":"https://github.com/1up-lab/OneupUploaderBundle/security/advisories/GHSA-x8wj-6m73-gfqp"},{"type":"FIX","url":"https://github.com/1up-lab/OneupUploaderBundle/commit/a6011449b716f163fe1ae323053077e59212350c"},{"type":"EVIDENCE","url":"https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2020-003.txt"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/1up-lab/oneupuploaderbundle","events":[{"introduced":"0"},{"fixed":"d59fcd2e5f675ee83c53965e16d21a942e90a9ef"},{"introduced":"8a6dc57c35e12fbc341e52e401a1d286475ec445"},{"fixed":"a6011449b716f163fe1ae323053077e59212350c"}],"database_specific":{"cpe":"cpe:2.3:a:1up:oneupuploaderbundle:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.9.3"},{"introduced":"1.9.4"},{"fixed":"2.1.5"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["1.9.2","2.1.4","2.1.3","2.1.2","2.1.1","2.1.0","2.0.7","2.0.6","2.0.5","2.0.4","2.0.3","2.0.2","2.0.1","2.0.0","1.9.1","1.9.0","1.8.3","1.8.2","1.8.1","1.8.0","1.7.7","1.7.6","1.7.5","1.7.4","1.7.3","1.7.2","1.7.1","1.7.0","1.6.0","1.5.0","1.4.0","v1.3.1","v1.2.2","v1.3.0","v1.2.0","v1.2.1","v1.1.0","v1.0.1","v1.0.0","v0.9.9","v0.9.8","v0.9.7","v0.9.6","v0.9.5","v0.9.4","v0.9.3","v0.9.2","v0.9.1","v0.9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-5237.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}