Description
An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file.
Remediation
References
https://www.youtube.com/watch?v=Tw8OhtVd-mE
http://buttercms.com
https://github.com/ButterCMS/buttercms-js
https://share.getcloudapp.com/nOuR70WB
Related Vulnerabilities
CVE-2023-26471 Vulnerability in maven package org.xwiki.platform:xwiki-platform-rendering-async-api
CVE-2022-43670 Vulnerability in maven package org.apache.sling:org.apache.sling.cms
CVE-2018-3750 Vulnerability in npm package deep-extend
CVE-2021-21290 Vulnerability in maven package io.netty:netty-testsuite
CVE-2021-23439 Vulnerability in npm package file-upload-with-preview