CVE-2018-9206 is a critical unauthenticated arbitrary file upload vulnerability affecting Blueimp jQuery-File-Upload versions up to 9.22.0. This flaw allows attackers to upload malicious files without authentication, leading to complete compromise of confidentiality, integrity, and availability. With a CVSS score of 9.8 (Critical) and an EPSS score indicating high exploitability, this vulnerability is easily exploited over the network with low attack complexity. Multiple public exploit modules, including Metasploit and Nuclei templates, are readily available, and it has garnered significant community discussion and media coverage, highlighting its widespread impact and ease of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.22.0CPE matchmatch criteria | cpe:2.3:a:jquery_file_upload_project:jquery_file_upload:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.