| Issue: |
|
|---|---|
| Date: |
|
| Severity: | Low |
| Requires Admin Access: | Yes |
| Fix Version: | n/a |
| Credit: | shaohong wu |
| Description: |
Authenticated users can uploaded bundles that contain files of any type. |
| Mitigation: |
None - This is by design to allow users to upload content with any extensions needed for their sites. |
| References |
CERT issue CVE-2017-3189 |