Description
An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file.
Remediation
References
http://buttercms.com
https://github.com/ButterCMS/buttercms-js
https://share.getcloudapp.com/nOuR70WB
https://www.youtube.com/watch?v=Tw8OhtVd-mE
Related Vulnerabilities
CVE-2019-0213 Vulnerability in maven package org.apache.archiva:archiva
CVE-2020-2143 Vulnerability in maven package org.jenkins-ci.plugins:logstash
CVE-2021-27185 Vulnerability in npm package samba-client
CVE-2017-5635 Vulnerability in maven package org.apache.nifi:nifi-framework-authorization
CVE-2019-10290 Vulnerability in maven package org.jenkins-ci.plugins:netsparker-cloud-scan