Vulnerability
Drag and Drop Multiple File Upload < 1.3.6.5 – File Upload Size Limit Bypass
Description
The plugin does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form. As a result, attackers could control the file length limit and bypass the limit set by admins in the contact form.
CVE-ID
CVE-2022-3282
Vendor
Codedropz
Product
Drag and Drop Multiple File Upload
Disclosure Timeline
Reported On: 26-08-2022
Made Public On: 2022-09-23
Fixed On: 23-09-2022
Credits
Sanjay Das