Description
An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file.
Remediation
References
http://buttercms.com
https://github.com/ButterCMS/buttercms-js
https://share.getcloudapp.com/nOuR70WB
https://www.youtube.com/watch?v=Tw8OhtVd-mE
Related Vulnerabilities
CVE-2022-36891 Vulnerability in maven package org.jenkins-ci.plugins:deployer-framework
CVE-2021-3503 Vulnerability in maven package org.wildfly:wildfly-metrics
CVE-2022-34800 Vulnerability in maven package tools.devnull:build-notifications
CVE-2017-1000118 Vulnerability in maven package com.typesafe.akka:akka-http-core_2.12
CVE-2019-16538 Vulnerability in maven package org.jenkins-ci.plugins:script-security