Unrestricted File Upload - Whenever an application server accepts a file without validating it or keeping any restriction, it is considered as an unrestricted file upload. The impact of unrestricted file upload can vary, including complete system takeover, an overloaded file system or database, forwarding attacks to back-end systems, client-side attacks, or simple defacement. It depends on what the application does with the uploaded file and especially where it is stored.
Reference Link - https://owasp.org/www-community/vulne...