The web application does not allow file uploads with dangerous extensions such as .php  webasyst-framework-master\wa-system\controller\waUploadJsonController.class.php  The above filtering is insufficient since it is possible to upload files with extensions that will be executed such as .phar    Tested on version: 2.7.2.732