Invicti detected an unrestricted file upload, which allows users to upload files to the web server.
If one of the uploaded files result a code execution, Invicti will report it as a separate issue.
The consequences of unrestricted file upload can vary, including complete system takeover, an overloaded file system or database, forwarding attacks to back-end systems, and simple defacement. It depends on what the application does with the uploaded file and especially where it is stored. Here is the list of attacks that the attacker might do:
.htaccess
file to allow him/her to execute specific scripts.You can search and find all vulnerabilities