Description
An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file.
Remediation
References
https://github.com/strapi/strapi
https://www.youtube.com/watch?v=LEeabouqRrg
Related Vulnerabilities
CVE-2016-6796 Vulnerability in maven package tomcat:jasper
CVE-2020-17527 Vulnerability in maven package org.apache.tomcat:tomcat-coyote
CVE-2018-19586 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web
CVE-2019-10793 Vulnerability in npm package dot-object
CVE-2020-26217 Vulnerability in maven package org.jvnet.hudson:xstream