CVE-2017-8080

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
05/05/2017
Last modified:
20/04/2025

Description

Atlassian Hipchat Server before 2.2.4 allows remote authenticated users with user level privileges to execute arbitrary code via vectors involving image uploads.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:atlassian:hipchat_server:*:*:*:*:*:*:*:* 2.2.3 (including)