Description
b3log Symphony (aka Sym) 2.6.0 allows remote attackers to upload and execute arbitrary JSP files via the name[] parameter to the /upload URI.
Remediation
References
https://github.com/b3log/symphony/issues/620
Related Vulnerabilities
CVE-2021-21174 Vulnerability in npm package electron
CVE-2021-21353 Vulnerability in maven package org.webjars.npm:pug-code-gen
CVE-2020-7782 Vulnerability in npm package spritesheet-js
CVE-2023-26480 Vulnerability in maven package org.xwiki.platform:xwiki-platform-livedata-webjar
CVE-2018-20834 Vulnerability in maven package org.webjars:tar