2amigos / yii2-file-upload-widget

BlueImp File Upload Widget for Yii2
Other
251 stars 140 forks source link

Zero-day in jQuery-File-Upload #152

Open MarcoPro opened 6 years ago

MarcoPro commented 6 years ago

A vulnerability has been discovered. It is recommended to update the plugin version.

https://www.zdnet.com/article/zero-day-in-popular-jquery-plugin-actively-exploited-for-at-least-three-years/?utm_campaign=Security%2BNewsletter&utm_medium=email&utm_source=Security_Newsletter_co_100

In addition there is another possible vulnerability that is described in the blueimp / jQuery-File-Upload website that is corrected with the version v9.25.1 Mitigates some Potential vulnerabilities with PHP+ImageMagick.

MarcoPro commented 6 years ago

imagen