CVE-2020-29441: Outsystems
Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.
An issue was discovered in the Upload Widget in OutSystems Platform 10 before 10.0.1019.0. An unauthenticated attacker can upload arbitrary files. In some cases, this attack may consume the available database space (Denial of Service), corrupt legitimate data if files are being processed asynchronously, or deny access to legitimate uploaded files.
Affected products
- Outsystems Outsystems: from 10, before 10.0.1019.0 (fixed in 10.0.1019.0)
Published 2020-11-30. Last modified 2026-06-17.