There is a file upload vulnerability in the Baidu WebUploader PHP demo. This vulnerability is caused by the lax filtering of file types or file extensions on the upload page of the WebUploader demo. Attackers can use the vulnerability to directly upload or simply bypass the restriction to upload script files, execute system commands, and obtain website server permissions. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021. Other reference:None