Описание
Unrestricted Upload of File with Dangerous Type in Strapi
An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file.
Пакеты
Наименование
strapi
npm
Затронутые версииВерсия исправления
<= 4.1.5
Отсутствует
Связанные уязвимости
CVSS3: 9.8
nvd
почти 4 года назад
An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file.