Description
An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbitrary code via a crafted SVG file.
Remediation
References
https://github.com/payloadcms/payload
https://www.youtube.com/watch?v=6CfhAxA3xdQ
Related Vulnerabilities
CVE-2022-0624 Vulnerability in maven package org.webjars.npm:parse-path
CVE-2021-23354 Vulnerability in npm package printf
CVE-2017-2607 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2021-23353 Vulnerability in maven package org.webjars.bowergithub.mrrio:jspdf
CVE-2021-32770 Vulnerability in npm package gatsby-source-wordpress