Description
An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file.
Remediation
References
http://buttercms.com
https://github.com/ButterCMS/buttercms-js
https://share.getcloudapp.com/nOuR70WB
https://www.youtube.com/watch?v=Tw8OhtVd-mE
Related Vulnerabilities
CVE-2023-24423 Vulnerability in maven package com.sonyericsson.hudson.plugins.gerrit:gerrit-trigger
CVE-2019-5786 Vulnerability in maven package org.webjars.npm:puppeteer
CVE-2014-0075 Vulnerability in maven package org.apache.tomcat:coyote
CVE-2023-36477 Vulnerability in maven package org.xwiki.platform:xwiki-platform-ckeditor-ui
CVE-2022-36889 Vulnerability in maven package org.jenkins-ci.plugins:deployer-framework