Beyond the Upload Button: A 10-Year Retrospective on Security Issues Within File Upload

Harun Oz, Güliz Seray Tuncay, Ahmet Arış, Amin Kharraz, Arif Selcuk Uluagac · IEEE Communications Magazine · 2025

File upload is a convenient feature offered by a plethora of applications and communication services in various interesting application contexts, such as IoT devices, smart home systems, and smart city infrastructures. This feature significantly enhances the efficiency of data exchange across communication networks and allows seamless sharing and management of content between users and systems. Despite its utility, this feature can introduce significant security issues, commonly known as unrestricted file upload (UFU) vulnerabilities, which pose widespread risks to the integrity and safety of communications systems. This study presents a comprehensive analysis of the security concerns associated with file uploads. Through a systematic examination of the vulnerability dataset, we analyze the nature of file upload vulnerabilities over the last decade. Our analysis reveals that many of these vulnerabilities are not complex to exploit, often requiring no user interaction or special privileges, yet they profoundly affect the confidentiality, integrity, and availability of systems. Our findings highlight the critical need for ongoing research and advancement in security measures to protect against such vulnerabilities by underscoring their impact on the entire communications landscape, from network operations to service delivery and user experience. Motivated by our findings, we highlight future research on file upload vulnerabilities and outline possible research directions.

Read the paper · More papers on PaperTik