Description
An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file.
Remediation
References
https://github.com/strapi/strapi
https://www.youtube.com/watch?v=LEeabouqRrg
Related Vulnerabilities
CVE-2017-7957 Vulnerability in maven package org.hudsonci.tools:xstream
CVE-2018-20676 Vulnerability in npm package bootstrap
CVE-2016-10694 Vulnerability in npm package alto-saxophone
CVE-2023-42399 Vulnerability in npm package jodit
CVE-2021-46384 Vulnerability in maven package net.mingsoft:ms-mcms