{"id":"CVE-2023-52086","details":"resumable.php (aka PHP backend for resumable.js) 0.1.4 before 3c6dbf5 allows arbitrary file upload anywhere in the filesystem via ../ in multipart/form-data content to upload.php. (File overwrite hasn't been possible with the code available in GitHub in recent years, however.)","modified":"2026-04-02T09:45:17.006802Z","published":"2023-12-26T18:15:09.030Z","references":[{"type":"REPORT","url":"https://github.com/dilab/resumable.php/issues/34"},{"type":"FIX","url":"https://github.com/dilab/resumable.php/commit/3c6dbf5170b01cbb712013c7d0a83f5aac45653b"},{"type":"FIX","url":"https://github.com/dilab/resumable.php/pull/27/commits/3e3c94d0302bb399a7611b4738a5a4dd0832a926"},{"type":"FIX","url":"https://github.com/dilab/resumable.php/pull/39/commits/408f54dff10e48befa44d417933787232a64304b"},{"type":"FIX","url":"https://github.com/dilab/resumable.php/pull/39/commits/d3552efd403e2d87407934477eee642836cab3b4"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dilab/resumable.php","events":[{"introduced":"0"},{"last_affected":"ad6ec9e06a0a3c89676071ede1243f6e7a77f0a2"},{"fixed":"3c6dbf5170b01cbb712013c7d0a83f5aac45653b"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"0.1.4"}]}}],"versions":["0.1.0","0.1.1","0.1.2","0.1.3","0.1.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-52086.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}