The code in https://github.com/blueimp/jQuery-File-Upload/blob/master/server/php/UploadHandler.php doesn't require any validation to upload files to the server. It also doesn't exclude file types. This allows for remote code execution. Upstream patch: https://github.com/blueimp/jQuery-File-Upload/pull/3514 References: http://www.vapidlabs.com/advisory.php?v=204
Created js-jquery-file-upload tracking bugs for this issue: Affects: fedora-all [bug 1638551]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.