{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "0.1.4"
              }
            ]
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "ad6ec9e06a0a3c89676071ede1243f6e7a77f0a2"
            },
            {
              "fixed": "3c6dbf5170b01cbb712013c7d0a83f5aac45653b"
            }
          ],
          "repo": "https://github.com/dilab/resumable.php",
          "type": "GIT"
        }
      ]
    }
  ],
  "details": "resumable.php (aka PHP backend for resumable.js) 0.1.4 before 3c6dbf5 allows arbitrary file upload anywhere in the filesystem via ../ in multipart/form-data content to upload.php. (File overwrite hasn't been possible with the code available in GitHub in recent years, however.)",
  "id": "CVE-2023-52086",
  "modified": "2026-04-01T23:09:23.203909888Z",
  "published": "2023-12-26T18:15:09.030Z",
  "references": [
    {
      "type": "REPORT",
      "url": "https://github.com/dilab/resumable.php/issues/34"
    },
    {
      "type": "FIX",
      "url": "https://github.com/dilab/resumable.php/commit/3c6dbf5170b01cbb712013c7d0a83f5aac45653b"
    },
    {
      "type": "FIX",
      "url": "https://github.com/dilab/resumable.php/pull/27/commits/3e3c94d0302bb399a7611b4738a5a4dd0832a926"
    },
    {
      "type": "FIX",
      "url": "https://github.com/dilab/resumable.php/pull/39/commits/408f54dff10e48befa44d417933787232a64304b"
    },
    {
      "type": "FIX",
      "url": "https://github.com/dilab/resumable.php/pull/39/commits/d3552efd403e2d87407934477eee642836cab3b4"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}