Описание
Unrestricted Upload of File with Dangerous Type in Payload
An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbitrary code via a crafted SVG file.
Пакеты
Наименование
payload
npm
Затронутые версииВерсия исправления
<= 0.15.0
0.15.1
Связанные уязвимости
CVSS3: 9.8
nvd
почти 4 года назад
An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbitrary code via a crafted SVG file.