Description
An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file.
Remediation
References
https://github.com/strapi/strapi
https://www.youtube.com/watch?v=LEeabouqRrg
Related Vulnerabilities
CVE-2018-20801 Vulnerability in npm package highcharts
CVE-2016-6809 Vulnerability in maven package org.apache.tika:tika-parsers
CVE-2017-7657 Vulnerability in maven package org.eclipse.jetty:jetty-client
CVE-2023-26487 Vulnerability in maven package org.webjars.npm:vega
CVE-2016-6816 Vulnerability in maven package org.apache.tomcat:tomcat-coyote