VWE-2017-4004 Printable Version

https://www.vaultwiki.org/pages/Book/Documentation/VWE-2017-4004
This page is a chapter in Info Known Vulnerabilities

This page has been seen 213,552 times.

    • Created by on
      Last updated by on
Common NameNone
VWE-IDVWE-2017-4004
Related ReportNone
SeverityMINOR
Exploit DifficultyEASY
PlatformAffects all platforms supported by the vulnerable versions.
DescriptionPermissions escalation. For some file types, a user can upload images with a higher width or height than allowed as long as the number of pixels is smaller than the permitted amount. Does not affect Lite versions.
DiscoveredAugust 12, 2017
ResolvedSeptember 24, 2017
Patches Available4.0.19 Patch Level 2
4.0.18 Patch Level 3
4.0.17 Patch Level 5
4.0.16 Patch Level 6
4.0.15 Patch Level 10
WorkaroundIn Content > Attachments, for each image file-type, set both maximum width and maximum height to the same number.
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.