Description
An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file.
Remediation
References
http://buttercms.com
https://github.com/ButterCMS/buttercms-js
https://share.getcloudapp.com/nOuR70WB
https://www.youtube.com/watch?v=Tw8OhtVd-mE
Related Vulnerabilities
CVE-2017-1000362 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2022-1233 Vulnerability in maven package org.webjars.bower:urijs
CVE-2017-18355 Vulnerability in npm package rendertron-middleware
CVE-2017-5662 Vulnerability in maven package org.eclipse.birt.runtime:org.apache.batik.dom
CVE-2022-29161 Vulnerability in maven package org.xwiki.platform:xwiki-platform-crypto