The product allows a file to be uploaded, but it relies on the file name or extension of the file to determine the appropriate behaviors. This could be used by attackers to cause the file to be misclassified and processed in a dangerous fashion.
Make decisions on the server side based on file content and not on file name or extension.
Our security experts can help you identify and remediate CWE-646 vulnerabilities in your codebase.
Get Security Assessment