Description
An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file.
Remediation
References
https://github.com/strapi/strapi
https://www.youtube.com/watch?v=LEeabouqRrg
Related Vulnerabilities
CVE-2020-2224 Vulnerability in maven package org.jenkins-ci.plugins:matrix-project
CVE-2021-25329 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2021-21120 Vulnerability in maven package org.webjars.npm:electron
CVE-2019-15302 Vulnerability in npm package cryptpad
CVE-2021-4279 Vulnerability in maven package org.webjars.bower:fast-json-patch