Описание
Unrestricted Upload of File with Dangerous Type in ButterCMS
An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file.
Пакеты
Наименование
buttercms
npm
Затронутые версииВерсия исправления
<= 1.2.8
Отсутствует
Связанные уязвимости
CVSS3: 9.8
nvd
почти 4 года назад
An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file.