Cross-Site Scripting https://wiki.owasp.org/index.php/Test_Upload_of_Unexpected_File_Types_(OTG-BUSLOGIC-008) https://wiki.owasp.org/index.php/Test_Upload_of_Malicious_Files_(OTG-BUSLOGIC-009) References Unrestricted File Upload [WEB] Bypass file upload filter with .htaccess Examples [2020] - Unrestricted File Upload Leads to XSS & Potential RCE [2019] - Unrestricted file upload in www.semrush.com > /my_reports/api/v1/upload/image